CVE-2013-10057 Details
Description
A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy operation overwrites a saved TRegistry class pointer on the stack. This allows remote attackers to execute arbitrary code in the context of the user by enticing them to visit a malicious webpage that instantiates the vulnerable ActiveX control. The vulnerability was discovered via its use in third-party software such as Logic Print 2013.
A stack-based buffer overflow vulnerability has been identified in the Synactis PDF In-The-Box ActiveX control, specifically in the PDF_IN_1.ocx file. The issue arises in the ConnectToSynactis method, where a long string can be passed to the ldCmdLine argument, intended for a WinExec call. This creates a strcpy operation that overwrites a saved pointer to a TRegistry class on the stack, allowing remote attackers to execute arbitrary code in the context of the user. The vulnerability can be exploited by tricking the user into visiting a malicious webpage that loads the vulnerable ActiveX control. This issue was discovered through its exploitation in third-party software, such as Logic Print 2013.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2025CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Synactis PDF In-The-Box | All versions |
CPE
Remediation
| |
| Logic Print 2013 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | New CVE Received | [email protected] |
Volerion