PT-2018-16316 · Foxit · Foxit Pdf Reader

Publicado

2018-08-01

·

Atualizado

2022-04-19

·

CVE-2018-3924

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader version 9.1.5096
Description A use-after-free issue exists in the JavaScript engine, allowing arbitrary code execution when a specially crafted PDF document is opened. This can be triggered by tricking a user into opening a malicious file. If the browser plugin extension is enabled, visiting a malicious site can also exploit this issue.
Recommendations For Foxit PDF Reader version 9.1.5096, consider disabling the JavaScript engine as a temporary workaround until a patch is available. Restrict access to malicious PDF files and avoid visiting untrusted websites with the browser plugin extension enabled.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3924

Produtos afetados

Foxit Pdf Reader