#VU16804 Out-of-bounds write in 3D Plugin Beta
Published: January 4, 2019
3D Plugin Beta
Foxit Software Inc.
Description
The vulnerability exists due to the improper handling of logic exception in IFXASSERT function when handling certain PDF file that embeds specifically crafted 3D content. A remote attacker can trick the victim into processing a specially crafted PDF file, trigger out-of-bounds write and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.