Use-after-free in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2024-30329
Published: March 8, 2024 / Updated: April 3, 2024
Vulnerability identifier: #VU88013
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-30329
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a use-after-free error when handling Annotation objects. A remote attacker can trick the victim to open a specially crafted PDF file and gain access to sensitive information.
Affected software
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows
Foxit PDF Reader for Windows
How to mitigate CVE-2024-30329
Install updates from vendor's website.
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 2024.1.0.23997
Foxit PDF Reader for Windows - update to 2024.1.0.23997
Foxit PDF Reader for Windows - update to 2024.1.0.23997