PT-2024-6538 · Foxit · Foxit Pdf Reader+1

Published

2024-09-26

·

Updated

2024-10-01

·

CVE-2024-41605

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Foxit PDF Reader versions prior to 2024.3 Foxit PDF Editor versions prior to 2024.3 and 13.x prior to 13.1.4
Description: The issue is related to errors in access control, allowing an attacker to replace an update file with a Trojan horse via side loading due to the lack of integrity validation for the updater. This may result in the execution of attacker-controlled code.
Recommendations: For Foxit PDF Reader versions prior to 2024.3, update to version 2024.3 or later. For Foxit PDF Editor versions prior to 2024.3, update to version 2024.3 or later. For Foxit PDF Editor 13.x versions prior to 13.1.4, update to version 13.1.4 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-07681
CVE-2024-41605

Affected Products

Foxit Pdf Editor
Foxit Pdf Reader