{ "id": "CVE-2024-35288", "sourceIdentifier": "cve@mitre.org", "published": "2024-10-09T04:15:08.233", "lastModified": "2024-10-09T04:15:08.233", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\\SYSTEM." } ], "metrics": {}, "references": [ { "url": "https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-nitro-pdf-pro/", "source": "cve@mitre.org" }, { "url": "https://seclists.org/fulldisclosure/2024/Sep/59", "source": "cve@mitre.org" }, { "url": "https://www.gonitro.com/support/downloads#securityUpdates", "source": "cve@mitre.org" } ] }