Medium severityNVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107733
CVE-2026-107733
Description
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, FrameOnCommand() handles CmdExec by passing a null current-tab pointer to RunWithExe(), which dereferences WindowTab::filePath. A local process in the same interactive Windows session, at an integrity level greater than or equal to SumatraPDF's under Windows UIPI, can dispatch CmdExec over DDE or WM_COPYDATA while no document tab is open, causing abrupt process termination and loss of unsaved state. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.6.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.