CVE-2017-10994: Critical severity foxit reader vulnerability
Published Jul 7, 2017
·Updated
Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<=8.3.0.14878
Foxitsoftware Phantompdf<=8.3.0.14878
Event History
Jul 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10994?
CVE-2017-10994 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2017-10994?
To fix CVE-2017-10994, update Foxit Reader or PhantomPDF to version 8.3.1 or later.
3
What software is affected by CVE-2017-10994?
CVE-2017-10994 affects Foxit Reader versions prior to 8.3.1 and Foxit PhantomPDF versions prior to 8.3.1.
4
What type of vulnerability is CVE-2017-10994?
CVE-2017-10994 is an Arbitrary Write vulnerability, allowing attackers to execute arbitrary code.
5
Can CVE-2017-10994 be exploited through the opening of a document?
Yes, CVE-2017-10994 can be exploited by opening a specially crafted document that triggers the vulnerability.