First published: Mon Jun 17 2019(Updated: )
A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing the URI string. An attacker can leverage this to gain remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Pdf Sdk Activex | <=5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19447 is high due to its potential for remote code execution.
To fix CVE-2018-19447, update Foxit Reader SDK (ActiveX) to version 5.5.0 or later.
Exploiting CVE-2018-19447 can allow an attacker to execute arbitrary code on the system via specially crafted PDF files.
Foxit Reader SDK (ActiveX) versions up to 5.4.0.1031 are affected by CVE-2018-19447.
No, Microsoft Windows itself is not vulnerable to CVE-2018-19447, but it may be affected if used with the vulnerable Foxit Reader SDK.