Executive brief
Investintech SlimPDFReader is a lightweight application used for viewing PDF documents. A security flaw in the software could allow a remote attacker to crash the application or potentially execute unauthorized code if a user is tricked into opening a specially crafted PDF file. Because the product has been discontinued by the manufacturer, no official security updates will be released to fix this issue.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in Investintech SlimPDFReader up to version 2.0.13. The flaw is located within the function sub_3B4610 in the SlimPDFReader.exe executable. An attacker can exploit this by delivering a malicious PDF file that, when opened by a user, triggers the overflow. This can lead to arbitrary code execution or application crashes. The vulnerability is considered remote as it can be triggered via network-delivered files, though it requires user interaction (UI:R). The vendor has stated the product is discontinued, and no patch is available.
Affected products
- Investintech SlimPDFReader up to 2.0.13
Timeline
- 2026-05-17: disclosed: Vulnerability published via VulDB/NVD
- 2026-05-17: advisory: Vendor confirmed product is discontinued and unsupported