Use-after-free error in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - #VU16794
Published: January 4, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to the use of page or pointer which has been closed or freed. A remote attacker can create a specially crafted PDF file, trick the victim into opening it, trigger use-after-free error and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Foxit PDF Editor (formerly Foxit PhantomPDF)
Remediation
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 9.4