Vulnerability record · CVE-2020-6113 · published 17 September 2020
CVE-2020-6113: Nitro Pro PDF object stream integer overflow leads to code execution
Gonitro · Nitro Pro
Nitro Pro 13.13.2.242 mishandles size calculation when updating its cross-reference table while parsing an object stream in a PDF. An integer overflow produces an undersized buffer, and initializing that buffer writes out of bounds, causing memory corruption that can lead to code execution. A crafted PDF is enough to reach the flaw, so the risk is real for anyone opening untrusted documents in the affected build.
Description
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform a calculation in order to allocate memory for the list of indirect objects. Due to an error when calculating this size, an integer overflow may occur which can result in an undersized buffer being allocated. Later when initializing this buffer, the application can write outside its bounds which can cause a memory corruption that can lead to code execution. A specially crafted document can be delivered to a victim in order to trigger this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with local vector and user interaction, but public exploit references and a very high EPSS score make timely patching important.
What it is
Nitro Pro 13.13.2.242 mishandles size calculation when updating its cross-reference table while parsing an object stream in a PDF. An integer overflow produces an undersized buffer, and initializing that buffer writes out of bounds, causing memory corruption that can lead to code execution. A crafted PDF is enough to reach the flaw, so the risk is real for anyone opening untrusted documents in the affected build.
Impact
An attacker who gets a victim to open a malicious PDF can corrupt memory and potentially execute code in the context of the Nitro Pro process, giving full control of confidentiality, integrity and availability on that host.
Attack surface
Reached locally when the application parses a specially crafted PDF object stream; the CVSS vector AV:L/PR:N/UI:R means no privileges are needed but user interaction (opening the document) is required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.65019 (99.2nd percentile) and both references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Nitro Pro past 13.13.2.242 to a vendor-supported fixed release.
- Block or sandbox opening of PDFs from untrusted sources until the upgrade is applied.
- Enforce attachment and download filtering at email and web gateways to reduce delivery of crafted PDFs.
- Run Nitro Pro with least privilege and enable OS exploit mitigations (ASLR, DEP, CFG) on endpoints.
Detection
- Monitor for Nitro Pro process crashes or abnormal terminations tied to PDF opening, especially repeated failures on the same file.
- Alert on child processes spawned by Nitro Pro, such as cmd.exe, powershell.exe or scripting hosts, which are not normal for a PDF reader.
- Hunt for PDFs containing object streams with unusually large or malformed /Size or /N values in cross-reference streams.
- Correlate endpoint telemetry for out-of-bounds write indicators (heap corruption, access violations) in Nitro Pro with recently opened documents.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1063 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1063 | ExploitThird Party Advisory |
Track CVE-2020-6113 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6113), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.