VYPR
Critical severityNVD Advisory· Published Aug 27, 2025· Updated Apr 15, 2026

CVE-2025-30057

CVE-2025-30057

Description

In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.