← Vulnerability feed

Vulnerability record · CVE-2020-6113 · published 17 September 2020

CVE-2020-6113: Nitro Pro PDF object stream integer overflow leads to code execution

Gonitro · Nitro Pro

Nitro Pro 13.13.2.242 mishandles size calculation when updating its cross-reference table while parsing an object stream in a PDF. An integer overflow produces an undersized buffer, and initializing that buffer writes out of bounds, causing memory corruption that can lead to code execution. A crafted PDF is enough to reach the flaw, so the risk is real for anyone opening untrusted documents in the affected build.

7.8 CVSS 3.1 High EPSS 65% · top 0.8% CWE-190 · Integer overflowCWE-131 · CWE-131
7.8CVSS 3.1 base score, v2 6.8
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform a calculation in order to allocate memory for the list of indirect objects. Due to an error when calculating this size, an integer overflow may occur which can result in an undersized buffer being allocated. Later when initializing this buffer, the application can write outside its bounds which can cause a memory corruption that can lead to code execution. A specially crafted document can be delivered to a victim in order to trigger this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.8 with local vector and user interaction, but public exploit references and a very high EPSS score make timely patching important.

What it is

Nitro Pro 13.13.2.242 mishandles size calculation when updating its cross-reference table while parsing an object stream in a PDF. An integer overflow produces an undersized buffer, and initializing that buffer writes out of bounds, causing memory corruption that can lead to code execution. A crafted PDF is enough to reach the flaw, so the risk is real for anyone opening untrusted documents in the affected build.

Impact

An attacker who gets a victim to open a malicious PDF can corrupt memory and potentially execute code in the context of the Nitro Pro process, giving full control of confidentiality, integrity and availability on that host.

Attack surface

Reached locally when the application parses a specially crafted PDF object stream; the CVSS vector AV:L/PR:N/UI:R means no privileges are needed but user interaction (opening the document) is required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.65019 (99.2nd percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Nitro Pro past 13.13.2.242 to a vendor-supported fixed release.
  • Block or sandbox opening of PDFs from untrusted sources until the upgrade is applied.
  • Enforce attachment and download filtering at email and web gateways to reduce delivery of crafted PDFs.
  • Run Nitro Pro with least privilege and enable OS exploit mitigations (ASLR, DEP, CFG) on endpoints.

Detection

  • Monitor for Nitro Pro process crashes or abnormal terminations tied to PDF opening, especially repeated failures on the same file.
  • Alert on child processes spawned by Nitro Pro, such as cmd.exe, powershell.exe or scripting hosts, which are not normal for a PDF reader.
  • Hunt for PDFs containing object streams with unusually large or malformed /Size or /N values in cross-reference streams.
  • Correlate endpoint telemetry for out-of-bounds write indicators (heap corruption, access violations) in Nitro Pro with recently opened documents.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6113 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-6146Nitro Pro heap buffer overflow in ICCBased colorspace stroke renderingNitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colo…EPSS 76%analysed8.8CVE-2020-6074Gonitro nitro pro use after free vulnerabilityAn exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-…EPSS 41%8.8CVE-2017-7442Gonitro nitro pro path traversal vulnerabilityNitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.EPSS 41%8.1CVE-2020-10223Gonitro nitro pro out-of-bounds write vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_pop…EPSS 2.5%8.1CVE-2020-10222Gonitro nitro pro vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.EPSS 2.5%7.8CVE-2021-21796Gonitro nitro pro use after free vulnerabilityAn exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an objec…EPSS 16%7.8CVE-2021-21797Gonitro nitro pro double free vulnerabilityAn exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference…EPSS 15%7.8CVE-2021-21798Gonitro nitro pro vulnerabilityAn exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document …EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2020-6113), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.