First published: Mon Jun 17 2019(Updated: )
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Pdf Sdk Activex | <=5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19446 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2018-19446, users should upgrade to a version of Foxit Reader SDK that is higher than 5.5.0.
It is not recommended to use Foxit Reader SDK version 5.4.0.1031 due to the significant security risks associated with CVE-2018-19446.
CVE-2018-19446 can facilitate remote code execution attacks through specially crafted PDF files.
CVE-2018-19446 specifically affects Foxit Reader SDK and does not directly impact Microsoft Windows itself.