CVE-2026-107733
Deferred Deferred - Pending Action

Privilege Escalation in SumatraPDF via DDE Command Execution

Vulnerability report for CVE-2026-107733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, FrameOnCommand() handles CmdExec by passing a null current-tab pointer to RunWithExe(), which dereferences WindowTab::filePath. A local process in the same interactive Windows session, at an integrity level greater than or equal to SumatraPDF's under Windows UIPI, can dispatch CmdExec over DDE or WM_COPYDATA while no document tab is open, causing abrupt process termination and loss of unsaved state. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF versions 3.6.1 and earlier contain a vulnerability where the FrameOnCommand() function incorrectly handles the CmdExec command. It passes a null pointer for the current tab to RunWithExe(), which then dereferences WindowTab::filePath. This flaw allows a local process in the same Windows session, with an integrity level equal to or higher than SumatraPDF's, to send malicious CmdExec commands via DDE or WM_COPYDATA when no document tab is open. This causes the application to terminate abruptly and lose any unsaved work.

Detection Guidance

This vulnerability involves SumatraPDF 3.6.1 or earlier handling CmdExec with a null current-tab pointer, leading to process termination. Detection requires checking for SumatraPDF versions 3.6.1 or older and monitoring for abrupt process crashes without user interaction.

Impact Analysis

This vulnerability can lead to abrupt termination of SumatraPDF, resulting in loss of unsaved documents and work. An attacker with local access and sufficient privileges could exploit this to crash the application at will, disrupting productivity. However, broader impacts like data theft or remote code execution are not claimed in the advisory.

Compliance Impact

This vulnerability causes abrupt process termination and loss of unsaved state in SumatraPDF, which may lead to data loss. However, no direct impact on compliance with GDPR or HIPAA is specified in the provided context.

Mitigation Strategies

Avoid using SumatraPDF 3.6.1 or earlier. Since no fixed version is available, consider uninstalling or replacing it with an alternative PDF reader until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107733. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart