First published: Mon Jun 17 2019(Updated: )
A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19452, this has a different free location and requires different JavaScript code for exploitation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF SDK ActiveX | <=5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19444 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2018-19444, update to a version of Foxit PDF SDK ActiveX that is above 5.5.0.
CVE-2018-19444 can allow an attacker to execute arbitrary code on the affected system through specially crafted PDF files.
Versions of Foxit PDF SDK ActiveX up to and including 5.5.0 are affected by CVE-2018-19444.
Yes, CVE-2018-19444 can be exploited remotely by sending a malicious PDF file to the target.