PT-2024-6538 · Foxit · Foxit Pdf Reader+1
Published
2024-09-26
·
Updated
2024-10-01
·
CVE-2024-41605
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Foxit PDF Reader versions prior to 2024.3
Foxit PDF Editor versions prior to 2024.3 and 13.x prior to 13.1.4
Description:
The issue is related to errors in access control, allowing an attacker to replace an update file with a Trojan horse via side loading due to the lack of integrity validation for the updater. This may result in the execution of attacker-controlled code.
Recommendations:
For Foxit PDF Reader versions prior to 2024.3, update to version 2024.3 or later.
For Foxit PDF Editor versions prior to 2024.3, update to version 2024.3 or later.
For Foxit PDF Editor 13.x versions prior to 13.1.4, update to version 13.1.4 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Pdf Editor
Foxit Pdf Reader