CVE-2018-3924
published 2018-08-01CVE-2018-3924: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF…
PriorityP352high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
44.14%
98.6th percentile
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit | — | — |
| foxitsoftware | foxit_reader | <= 9.1.0.5096 | — |
| foxitsoftware | phantompdf | <= 9.1.0.5096 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Foxit PDF Reader JavaScript Remote Code Execution Vulns
blogs_talos·2018-07-19·CVSS 8.8
CVE-2018-3924 [HIGH] Vulnerability Spotlight: Foxit PDF Reader JavaScript Remote Code Execution Vulns
## Vulnerability Spotlight: Foxit PDF Reader JavaScript Remote Code Execution Vulns
## Overview Discovered by Aleksandar Nikolic of Cisco Talos. Talos is disclosing a pair of vulnerabilities in Foxit PDF Reader. Foxit PDF Reader is a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available.
## TALOS-2018-0588 TALOS-2018-0588 / CVE-2018-3924 is an exploitable user-after-free vulnerability that exists in the JavaScript engine of Foxit's PDF Reader. As a complete feature-rich PDF reader Foxit supports JavaScript for interactive documents and dynamic forms. When executing embedded JavaScript code a document can be cloned, which frees a lot of used objects, but the JavaSc
Talos
Vulnerability Spotlight: Foxit PDF Reader JavaScript Remote Code Execution Vulns
blogs_talos·2018-07-19·CVSS 8.8
CVE-2018-3924 [HIGH] Vulnerability Spotlight: Foxit PDF Reader JavaScript Remote Code Execution Vulns
## OverviewDiscovered by Aleksandar Nikolic of Cisco Talos.Talos is disclosing a pair of vulnerabilities in Foxit PDF Reader. Foxit PDF Reader is a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available.
## TALOS-2018-0588 TALOS-2018-0588 / CVE-2018-3924 is an exploitable user-after-free vulnerability that exists in the JavaScript engine of Foxit's PDF Reader. As a complete feature-rich PDF reader Foxit supports JavaScript for interactive documents and dynamic forms. When executing embedded JavaScript code a document can be cloned, which frees a lot of used objects, but the JavaScript can continue to execute, potentially leading to a user-after-free condition. This
2018-08-01
Published