Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107735— SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initialization)

Quick assessment

Affected
sumatrapdfreader sumatrapdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SumatraPDF 是 Windows 平台上的一款多格式文档阅读器。在版本 3.6.1 及更早版本中, 函数在初始化时,会将 配置文件的路径与 变量(初始值设为 ,即允许所有权限)结合,并且仅通过逻辑“或”(OR)操作来合并权限位。这种实现方式导致 INI 文件中的权限限制配置无法实际撤销任何权限。因此,如果通过该 INI 文件部署 SumatraPDF,无论配置文件是否存在格式错误,还是权限设置值为零,均可能导致磁盘访问、网络、打印、注册表、剪贴板、偏好设置以及全屏模式等方面的策略限制被静默绕过。 需要注意的

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107735

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initialization)
Source: CVE Program / CVE List V5
Vulnerability Description
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, InitializePolicies() starts the sumatrapdfrestrict.ini path with gPolicyRestrictions set to Perm::All and only ORs permission bits, so the INI file never revokes permissions. Deploying SumatraPDF with this INI file, including a malformed file or zero-valued permission settings, can silently bypass configured disk, network, printing, registry, clipboard, preference, and fullscreen restrictions. The -restrict command-line path works correctly and is not affected. No fixed version is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sumatrapdfreader sumatrapdf <= 3.6.1 -

II. Public POCs for CVE-2026-107735

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107735

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107735 (1)

Vendor Advisories for CVE-2026-107735 (1)

Same Patch Batch · sumatrapdfreader · 2026-10-08 · 11 CVEs total

CVE-2026-107732 8.4 HIGH SumatraPDF: Markup/command-link injection into UI notification text
CVE-2026-107734 7.1 HIGH SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi
CVE-2026-107802 7.1 HIGH SumatraPDF — Windows command-line argument injection in AI selection-translate
CVE-2026-107733 6.8 MEDIUM SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open
CVE-2026-107736 6.8 MEDIUM SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
CVE-2026-107738 6.8 MEDIUM SumatraPDF: Untrusted binary record offset used without lower-bound validation
CVE-2026-107737 5.7 MEDIUM SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup
CVE-2026-107731 5.5 MEDIUM SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se
CVE-2026-107729 5.5 MEDIUM SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes
CVE-2026-107730 5.5 MEDIUM SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read

IV. Related Vulnerabilities

V. Comments for CVE-2026-107735

No comments yet


Leave a comment