VYPR
Unrated severityNVD Advisory· Published Jul 24, 2022· Updated Apr 15, 2025

Anvsoft PDFMate PDF Converter Pro memory corruption

CVE-2017-20144

Description

A vulnerability has been found in Anvsoft PDFMate PDF Converter Pro 1.7.5.0 and classified as critical. The manipulation leads to memory corruption. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in PDFMate PDF Converter Pro 1.7.5.0 allows remote attackers to cause memory corruption via a crafted HTML file.

Vulnerability

A local buffer overflow vulnerability exists in PDFMate PDF Converter Pro version 1.7.5.0. The flaw resides in the Convert_Pro.dll library located in the installation directory C:\Program Files\Anvsoft\PDFMate PDF Converter Professional. When the application converts an HTML file, the library processes user-supplied data without proper bounds checking, leading to memory corruption. The vulnerability is triggered by including a large Unicode string in the HTML template [1].

Exploitation

An attacker can exploit this vulnerability remotely by convincing a user to open a malicious HTML file with the affected software. No authentication is required, but user interaction is necessary. The attacker crafts an HTML file containing an oversized Unicode payload. When the user initiates a conversion operation (e.g., HTML to PDF), the Convert_Pro.dll processes the payload, overwriting registers and potentially hijacking execution flow [1].

Impact

Successful exploitation allows an attacker to corrupt memory and potentially execute arbitrary code in the context of the affected application. This could lead to full compromise of the local system, including data disclosure, modification, or denial of service. The CVSS score of 5.9 (Medium) reflects the need for user interaction and the local nature of the attack [1].

Mitigation

As of the publication date, no official patch or fixed version has been released by Anvsoft. Users are advised to exercise caution when opening HTML files from untrusted sources and to consider using alternative PDF conversion software. The vulnerability has been publicly disclosed, increasing the risk of exploitation [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.