Use-after-free error in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - #VU16794

 

Use-after-free error in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - #VU16794

Published: January 4, 2019


Vulnerability identifier: #VU16794
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to the use of page or pointer which has been closed or freed. A remote attacker can create a specially crafted PDF file, trick the victim into opening it, trigger use-after-free error and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)

Remediation

Update to version 9.4.

Foxit PDF Reader for Windows - update to 9.4
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 9.4

External References

Related Security Bulletins