Executive brief
pdfforge PDF Architect is a PDF editing and creation tool used by businesses and professionals. A flaw in its activation-service process allows attackers who can run code on a system to escalate their privileges to administrator level, gaining full control of the machine and enabling them to install malware, steal data, or sabotage operations.
Technical details
This vulnerability is a local privilege escalation (LPE) in the activation-service component of PDF Architect, caused by an uncontrolled search path element—the service loads a library from an unsecured or predictable location on the filesystem. An attacker with low-privileged code execution on the target system can exploit this by placing a malicious library in the search path, which will be loaded and executed in the SYSTEM context when the activation-service runs. No network access or user interaction is required beyond initial code execution. Exploitation results in full system compromise. The vulnerability was disclosed on 2026-08-31 after a coordinated disclosure process.
Affected products
- pdfforge PDF Architect
Timeline
- 2026-03-31: disclosed: Vulnerability reported to vendor
- 2026-08-31: advisory: Coordinated public release of advisory (ZDI-26-615)