Use-after-free in Foxit PDF Editor (formerly Foxit PhantomPDF) - CVE-2024-7725
Published: October 1, 2024 / Updated: October 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The
vulnerability exists due to a use-after-free error when handling PDF
files. A remote attacker can trick the victim into opening a specially
crafted PDF file, trigger a use-after-free error and execute arbitrary
code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Foxit PDF Editor for Mac (formerly PhantomPDF)
How to mitigate CVE-2024-7725
Foxit PDF Editor for Mac (formerly PhantomPDF) - addressed in versions 11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538