CVE-2018-1176
published 2018-05-17CVE-2018-1176: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to…
PriorityP348high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.51%
88.0th percentile
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ePub files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5442.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit_reader | — | — |
| foxitsoftware | foxit_reader | <= 9.0.1.1049 | — |
| foxitsoftware | phantompdf | <= 9.0.1.1049 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Volexity
Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
blogs_volexity·2018-08-27·CVSS 8.1
CVE-2018-11776 [HIGH] Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
Threat Intelligence
# Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
August 27, 2018
Matthew Meltzer, Sean Koessel, and Steven Adair
On Wednesday, August 22, 2018, the Apache Foundation released a security bulletin for a critical vulnerability in the Apache Struts framework. This bulletin stated that the vulnerability, assigned CVE-2018-11776, could potentially allow for remote code execution if successfully exploited. Only a day later, on August 23, 2018, a researcher released a proof of concept (PoC) exploit for this vulnerability.
- https://github.com/jas502n/St2-057/blob/master/README.md
On August 24, 2018, a Python script was released to make use of the exploit:
- https://github.com/pr4jwal/quick-scripts/blob/master/s2-057.py
Volexity
Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
blogs_volexity·2018-08-27·CVSS 8.1
CVE-2018-11776 [HIGH] Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
Threat Intelligence
## Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
August 27, 2018
Matthew Meltzer, Sean Koessel, and Steven Adair
On Wednesday, August 22, 2018, the Apache Foundation released a security bulletin for a critical vulnerability in the Apache Struts framework. This bulletin stated that the vulnerability, assigned CVE-2018-11776 , could potentially allow for remote code execution if successfully exploited. Only a day later, on August 23, 2018, a researcher released a proof of concept (PoC) exploit for this vulnerability.
https://github.com/jas502n/St2-057/blob/master/README.md
On August 24, 2018, a Python script was released to make use of the exploit:
https://github.com/pr4jwal/quick-scripts/blob/master/s2-057.py
S
Unit42
Threat Brief: Information on Critical Apache Struts Vulnerability CVE-2018-11776
blogs_unit42·2018-08-24·CVSS 8.8
CVE-2018-11776 [HIGH] Threat Brief: Information on Critical Apache Struts Vulnerability CVE-2018-11776
Situation Overview
On August 22, 2018, the Apache Foundation released a critical security update for CVE-2018-1176, a remote code execution vulnerability affecting Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16. The Apache Foundation has urged everyone to apply the security updates as soon as possible.
This blog is to provide information to help organizations assess their risk of the vulnerability and to inform Palo Alto Networks customers of protections in place that can help mitigate their risk until they can apply the security updates. Palo Alto Networks customers who have deployed the latest vulnerability signatures released on August 24, 2018, are protected.
Vulnerability Information
According to both the Apache Foundation and security researcher Man Yue Mo, this vulnerabi
Unit42
Threat Brief: Information on Critical Apache Struts Vulnerability CVE-2018-11776
blogs_unit42·2018-08-24·CVSS 8.8
CVE-2018-11776 [HIGH] Threat Brief: Information on Critical Apache Struts Vulnerability CVE-2018-11776
## Threat Brief: Information on Critical Apache Struts Vulnerability CVE-2018-11776
Unit 42
Published: August 24, 2018
High Profile Threats
Vulnerabilities
Apache
CVE-2018-11776
Protections
Struts
Situation Overview
On August 22, 2018, the Apache Foundation released a critical security update for CVE-2018-1176 , a remote code execution vulnerability affecting Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16. The Apache Foundation has urged everyone to apply the security updates as soon as possible.
This blog is to provide information to help organizations assess their risk of the vulnerability and to inform Palo Alto Networks customers of protections in place that can help mitigate their risk until they can apply the security updates. Palo Alto Networks customers who have d
2018-05-17
Published