#VU27095 Heap-based buffer overflow in 3D Plugin Beta - CVE-2020-10896
Published: April 22, 2020
3D Plugin Beta
Foxit Software Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the handling of U3D objects in PDF files. A remote attacker can trick a victim to open a specially crafted file or visit a malicious page, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.