CVE-2017-14458
published 2018-04-23CVE-2017-14458: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A specially crafted PDF…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.41%
87.6th percentile
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_reader | — | — |
| talos | foxit | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
blogs_talos·2018-04-19·CVSS 8.8
CVE-2017-14458 [HIGH] Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
### Overview Talos is disclosing five vulnerabilities in Foxit PDF Reader.Foxit PDF Readeris a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available. Update to the current version ofFoxit PDF Reader.
### DetailsVulnerabilities Discovered by Aleksandar Nikolic
#### TALOS-2017-0506 TALOS-2017-0506 / CVE-2017-14458 in an exploitable use-after-free vulnerability that exists specifically in the JavaScript engine of Foxit PDF Reader. When executing embedded JavaScript code, a document can be closed, which essentially frees up a lot of used objects, but the JavaScript can continue to execute. Taking advantage of this, a specially crafted PDF document can trigger a previo
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
blogs_talos·2018-04-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
## Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
## Overview Talos is disclosing five vulnerabilities in Foxit PDF Reader. Foxit PDF Reader is a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available. Update to the current version of Foxit PDF Reader .
## Details Vulnerabilities Discovered by Aleksandar Nikolic
## TALOS-2017-0506 TALOS-2017-0506 / CVE-2017-14458 in an exploitable use-after-free vulnerability that exists specifically in the JavaScript engine of Foxit PDF Reader. When executing embedded JavaScript code, a document can be closed, which essentially frees up a lot of used objects, but the JavaScript can continue to execute. Taking advant
http://www.securityfocus.com/bid/103942http://www.securitytracker.com/id/1040733https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0506http://www.securityfocus.com/bid/103942http://www.securitytracker.com/id/1040733https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0506
2018-04-23
Published