First published: Wed Apr 13 2016(Updated: )
The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | =6.1 | |
Foxit Reader | =6.1.2 | |
Foxit Reader | =6.1.4 | |
Foxit Reader | =6.2 | |
Foxit Reader | =6.2.1 | |
Foxit Reader | =7.0 | |
Foxit Reader | =7.0.1 | |
Foxit Reader | =7.0.6 | |
Foxit Reader | =7.1.5 | |
Foxit Reader | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8843 is classified as a privilege escalation vulnerability.
To fix CVE-2015-8843, update Foxit Reader to version 7.2.2 or later.
CVE-2015-8843 affects Foxit Reader versions 6.1 through 6.2.x and 7.x before 7.2.2.
CVE-2015-8843 can be exploited by local users with access to the system.
The impact of CVE-2015-8843 enables local users to gain elevated privileges through memory corruption.