PT-2024-8734 · Foxit · Foxit Pdf Reader+1

Published

2024-08-03

·

Updated

2024-10-18

·

CVE-2024-7725

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader (affected versions not specified) Foxit PDF Editor (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the AcroForm component of Foxit PDF Reader and Foxit PDF Editor. This vulnerability allows remote attackers to execute arbitrary code on affected installations. User interaction is required to exploit this vulnerability, where the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms, resulting from the lack of validating the existence of an object prior to performing operations on the object.
Recommendations For Foxit PDF Reader, update to a version that addresses the use-after-free vulnerability in the AcroForm component. For Foxit PDF Editor, update to a version that addresses the use-after-free vulnerability in the AcroForm component. As a temporary workaround, consider restricting the handling of AcroForms in Foxit PDF Reader and Foxit PDF Editor until a patch is available.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-10338
CVE-2024-7725
ZDI-24-1127

Affected Products

Foxit Pdf Editor
Foxit Pdf Reader