#VU12048 Type confusion in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF)
Published: April 20, 2018
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit Software Inc.
Description
The weakness exists when executing certain XFA functions in crafted PDF files since the application could transform non-CXFA_Object to CXFA_Object without judging the data type and use the discrepant CXFA_Object to get layout object directly. A remote attacker can trick the victim into opening a specially crafted file, trigger type confusion error and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.