CVE-2018-14270: Incorrect Type Cast
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeDataObject method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6033.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14270?
CVE-2018-14270 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-14270?
To remediate CVE-2018-14270, users should update Foxit Reader or PhantomPDF to version 9.1.0.5097 or later.
What kind of attacks are possible with CVE-2018-14270?
CVE-2018-14270 allows remote attackers to execute arbitrary code if a user opens a malicious file or visits a harmful webpage.
Which versions of Foxit Reader are affected by CVE-2018-14270?
CVE-2018-14270 affects Foxit Reader versions up to and including 9.1.0.5096.
Do I need to take any action if I am using a version of Foxit Reader later than 9.1.0.5096 concerning CVE-2018-14270?
If you are using a version of Foxit Reader later than 9.1.0.5096, you are not affected by CVE-2018-14270 and no action is needed.