Use-after-free error in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - #VU16798
Published: January 4, 2019 / Updated: January 4, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to the use of document and its auxiliary objects which have been closed after calling closeDocfunction. A remote attacker can create a specially crafted PDF file, trick the victim into opening it, trigger use-after-free error and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Foxit PDF Editor (formerly Foxit PhantomPDF)
Remediation
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 9.4