CVE-2018-14292: Use After Free
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. By manipulating a document's elements, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6232.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14292?
CVE-2018-14292 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-14292?
To fix CVE-2018-14292, update Foxit Reader and Foxit PhantomPDF to the latest versions beyond 9.1.0.5096.
What impact does CVE-2018-14292 have on users?
CVE-2018-14292 allows attackers to execute arbitrary code, which could lead to data theft or system compromise.
Is user interaction required to exploit CVE-2018-14292?
Yes, user interaction is required for CVE-2018-14292 as it necessitates opening a malicious file or visiting an infected webpage.
Which software versions are affected by CVE-2018-14292?
CVE-2018-14292 affects Foxit Reader and Foxit PhantomPDF versions up to and including 9.1.0.5096.