CVE-2017-14828: Incorrect Type Cast
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the w method of XFA Layout objects. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5020.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14828?
CVE-2017-14828 has a high severity rating due to its potential for remote code execution.
How does CVE-2017-14828 exploit work?
CVE-2017-14828 requires user interaction, as it is exploited through a malicious page or file opened by the user.
What versions of Foxit Reader are affected by CVE-2017-14828?
CVE-2017-14828 specifically affects Foxit Reader version 8.3.1.21155.
How can I mitigate the risks associated with CVE-2017-14828?
To mitigate risks from CVE-2017-14828, users should update to a patched version of Foxit Reader.
What type of defense is needed against CVE-2017-14828?
Implementing strong email and web security measures can help defend against the exploitation of CVE-2017-14828.