PT-2022-21456 · Foxit · Foxit Pdf Reader
Aleksandar Nikolic
·
Published
2022-11-14
·
Updated
2022-12-27
·
CVE-2022-32774
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foxit Software's PDF Reader version 12.0.1.12430
Description
A use-after-free issue exists in the JavaScript engine of Foxit Software's PDF Reader. This can be triggered by a specially-crafted PDF document that prematurely deletes objects associated with pages, leading to the reuse of previously freed memory and potentially allowing arbitrary code execution. An attacker can exploit this by tricking a user into opening a malicious file or by having the user visit a specially-crafted malicious site if the browser plugin extension is enabled.
Recommendations
For version 12.0.1.12430, consider disabling the JavaScript engine in the PDF Reader as a temporary workaround until a patch is available. Restrict access to malicious PDF files and avoid visiting untrusted websites with the browser plugin extension enabled.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Pdf Reader