Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107737— SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup

Quick assessment

Affected
sumatrapdfreader sumatrapdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SumatraPDF 是一款支持多格式的 Windows 平台 PDF 阅读器。在版本 3.6.1 及更早版本中,以及在预发布版本 3.7.0.20369 中,当 WebView2 缺失或无法初始化时,ParseProtoUrl() 函数会接受来自“its://” URL 的带签名主机组件,并且 FindHtmlWindowById() 会直接将其用作对全局数组 gHtmlWindows 的索引。通过 IE 回退后端打开构造恶意且包含负数或超出范围的窗口标识符的 CHM 文件,可能导致越界指针读取,进而引发无效的回

CVSS 5.7 · Medium

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107737

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup
Source: CVE Program / CVE List V5
Vulnerability Description
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数组索引的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sumatrapdfreader sumatrapdf <= 3.6.1 -

II. Public POCs for CVE-2026-107737

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107737

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107737 (1)

Vendor Advisories for CVE-2026-107737 (1)

Same Patch Batch · sumatrapdfreader · 2026-10-08 · 11 CVEs total

CVE-2026-107732 8.4 HIGH SumatraPDF: Markup/command-link injection into UI notification text
CVE-2026-107734 7.1 HIGH SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi
CVE-2026-107802 7.1 HIGH SumatraPDF — Windows command-line argument injection in AI selection-translate
CVE-2026-107733 6.8 MEDIUM SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open
CVE-2026-107736 6.8 MEDIUM SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
CVE-2026-107738 6.8 MEDIUM SumatraPDF: Untrusted binary record offset used without lower-bound validation
CVE-2026-107731 5.5 MEDIUM SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se
CVE-2026-107729 5.5 MEDIUM SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes
CVE-2026-107730 5.5 MEDIUM SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read
CVE-2026-107735 5.4 MEDIUM SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia

IV. Related Vulnerabilities

V. Comments for CVE-2026-107737

No comments yet


Leave a comment