PT-2019-9815 · Foxit · Foxit Reader Sdk (Activex) Professional
Published
2019-06-17
·
Updated
2019-06-18
·
CVE-2018-19449
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foxit Reader SDK (ActiveX) Professional version 5.4.0.1031
Description
The issue allows a File Write to occur for specially crafted PDF files when the JavaScript API
Doc.exportAsFDF is used. This can be leveraged by an attacker to gain remote code execution.Recommendations
For Foxit Reader SDK (ActiveX) Professional version 5.4.0.1031, consider disabling the
Doc.exportAsFDF JavaScript API until a patch is available to prevent potential remote code execution.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Reader Sdk (Activex) Professional