Vulnerability record · CVE-2020-6146 · published 16 September 2020
CVE-2020-6146: Nitro Pro heap buffer overflow in ICCBased colorspace stroke rendering
Gonitro · Nitro Pro
Nitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colorspace. A length read from the file is used as a loop sentinel while writing into a fixed-size heap buffer, allowing an out-of-bounds write. Because the flaw is reachable through a crafted document, it matters to anyone opening untrusted PDFs in the affected versions.
Description
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a length from the file and use it as a loop sentinel when writing data into the member of an object. Due to the object member being a buffer of a static size allocated on the heap, this can result in a heap-based buffer overflow. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a remotely deliverable heap overflow with high EPSS and public exploit detail, but it requires user interaction and is not known to be exploited in the wild or in KEV.
What it is
Nitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colorspace. A length read from the file is used as a loop sentinel while writing into a fixed-size heap buffer, allowing an out-of-bounds write. Because the flaw is reachable through a crafted document, it matters to anyone opening untrusted PDFs in the affected versions.
Impact
An attacker who gets a victim to open a crafted document can corrupt heap memory and potentially achieve code execution in the context of the Nitro Pro process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vulnerability is reached by loading a specially crafted document in Nitro Pro, so it requires user interaction to open the file. The network vector and no privileges required reflect delivery of the document rather than direct remote access to the application.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high at 0.76089 (99.5th percentile), and the only references are Talos advisory links tagged Exploit, indicating public exploit detail exists. No ransomware group use is documented.
What to do
- Upgrade Nitro Pro to a version later than 13.16.2.300, or to the vendor's current supported release.
- If immediate upgrade is not possible, restrict opening of untrusted PDFs in Nitro Pro and use an alternative viewer for external documents.
- Apply email and web gateway filtering to block or quarantine untrusted PDF attachments and downloads.
- Run Nitro Pro with least privilege and enable OS-level exploit mitigations such as DEP and ASLR.
- Monitor vendor advisories for updated fixed versions and confirm the installed build number.
Detection
- Monitor for Nitro Pro process crashes or abnormal terminations when opening PDF files, especially heap-related faults.
- Hunt for PDFs containing ICCBased colorspace objects with unusual or oversized length fields in stroke color definitions.
- Correlate endpoint telemetry for Nitro Pro spawning child processes or writing executables after a document is opened.
- Review email and proxy logs for PDF attachments from untrusted senders delivered to users running affected Nitro Pro builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1084 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1084 | ExploitThird Party Advisory |
Track CVE-2020-6146 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6146), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.