← Vulnerability feed

Vulnerability record · CVE-2020-6146 · published 16 September 2020

CVE-2020-6146: Nitro Pro heap buffer overflow in ICCBased colorspace stroke rendering

Gonitro · Nitro Pro

Nitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colorspace. A length read from the file is used as a loop sentinel while writing into a fixed-size heap buffer, allowing an out-of-bounds write. Because the flaw is reachable through a crafted document, it matters to anyone opening untrusted PDFs in the affected versions.

8.8 CVSS 3.1 High EPSS 76% · top 0.5% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a length from the file and use it as a loop sentinel when writing data into the member of an object. Due to the object member being a buffer of a static size allocated on the heap, this can result in a heap-based buffer overflow. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is a remotely deliverable heap overflow with high EPSS and public exploit detail, but it requires user interaction and is not known to be exploited in the wild or in KEV.

What it is

Nitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colorspace. A length read from the file is used as a loop sentinel while writing into a fixed-size heap buffer, allowing an out-of-bounds write. Because the flaw is reachable through a crafted document, it matters to anyone opening untrusted PDFs in the affected versions.

Impact

An attacker who gets a victim to open a crafted document can corrupt heap memory and potentially achieve code execution in the context of the Nitro Pro process. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The vulnerability is reached by loading a specially crafted document in Nitro Pro, so it requires user interaction to open the file. The network vector and no privileges required reflect delivery of the document rather than direct remote access to the application.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high at 0.76089 (99.5th percentile), and the only references are Talos advisory links tagged Exploit, indicating public exploit detail exists. No ransomware group use is documented.

What to do

  • Upgrade Nitro Pro to a version later than 13.16.2.300, or to the vendor's current supported release.
  • If immediate upgrade is not possible, restrict opening of untrusted PDFs in Nitro Pro and use an alternative viewer for external documents.
  • Apply email and web gateway filtering to block or quarantine untrusted PDF attachments and downloads.
  • Run Nitro Pro with least privilege and enable OS-level exploit mitigations such as DEP and ASLR.
  • Monitor vendor advisories for updated fixed versions and confirm the installed build number.

Detection

  • Monitor for Nitro Pro process crashes or abnormal terminations when opening PDF files, especially heap-related faults.
  • Hunt for PDFs containing ICCBased colorspace objects with unusual or oversized length fields in stroke color definitions.
  • Correlate endpoint telemetry for Nitro Pro spawning child processes or writing executables after a document is opened.
  • Review email and proxy logs for PDF attachments from untrusted senders delivered to users running affected Nitro Pro builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6146 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-6074Gonitro nitro pro use after free vulnerabilityAn exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-…EPSS 41%8.8CVE-2017-7442Gonitro nitro pro path traversal vulnerabilityNitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.EPSS 41%8.1CVE-2020-10223Gonitro nitro pro out-of-bounds write vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_pop…EPSS 2.5%8.1CVE-2020-10222Gonitro nitro pro vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.EPSS 2.5%7.8CVE-2021-21796Gonitro nitro pro use after free vulnerabilityAn exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an objec…EPSS 16%7.8CVE-2021-21797Gonitro nitro pro double free vulnerabilityAn exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference…EPSS 15%7.8CVE-2021-21798Gonitro nitro pro vulnerabilityAn exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document …EPSS 16%7.8CVE-2020-6113Nitro Pro PDF object stream integer overflow leads to code executionNitro Pro 13.13.2.242 mishandles size calculation when updating its cross-reference table while parsing an object stream in a PDF. An integer overflo…EPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2020-6146), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.