First published: Tue Oct 02 2018(Updated: )
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PhantomPDF | <=9.2.0.9297 | |
Foxit Reader | <=9.2.0.9297 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3962 is classified as a high severity vulnerability due to the potential for remote code execution through crafted PDF files.
To fix CVE-2018-3962, update Foxit PDF Reader or Foxit PhantomPDF to version 9.2.0.9297 or later.
CVE-2018-3962 can lead to use-after-free conditions, allowing attackers to execute arbitrary code on the victim’s system.
CVE-2018-3962 affects Foxit Reader and PhantomPDF versions up to 9.2.0.9297.
Yes, CVE-2018-3962 can be exploited remotely if a user opens a maliciously crafted PDF file.