First published: Mon Jun 17 2019(Updated: )
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Pdf Sdk Activex | <=5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19445 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-19445, update to Foxit Reader SDK (ActiveX) version 5.5.0 or later.
CVE-2018-19445 affects Foxit PDF SDK (ActiveX) Professional versions up to 5.4.0.1031.
An attacker can exploit CVE-2018-19445 through specially crafted PDF files to execute arbitrary commands on the host system.
CVE-2018-19445 is not specific to any operating system but affects the application running on Microsoft Windows.