PT-2022-21456 · Foxit · Foxit Pdf Reader

Aleksandar Nikolic

·

Published

2022-11-14

·

Updated

2022-12-27

·

CVE-2022-32774

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit Software's PDF Reader version 12.0.1.12430
Description A use-after-free issue exists in the JavaScript engine of Foxit Software's PDF Reader. This can be triggered by a specially-crafted PDF document that prematurely deletes objects associated with pages, leading to the reuse of previously freed memory and potentially allowing arbitrary code execution. An attacker can exploit this by tricking a user into opening a malicious file or by having the user visit a specially-crafted malicious site if the browser plugin extension is enabled.
Recommendations For version 12.0.1.12430, consider disabling the JavaScript engine in the PDF Reader as a temporary workaround until a patch is available. Restrict access to malicious PDF files and avoid visiting untrusted websites with the browser plugin extension enabled.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2022-32774

Affected Products

Foxit Pdf Reader