CVE-2018-3996: Use After Free
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3996?
CVE-2018-3996 has been rated with high severity due to its potential for arbitrary code execution.
How do I fix CVE-2018-3996?
To fix CVE-2018-3996, users should update Foxit PDF Reader or PhantomPDF to version 9.2.1 or later.
What platforms are affected by CVE-2018-3996?
CVE-2018-3996 affects Foxit Reader and PhantomPDF versions up to 9.2.0.9297 running on Windows.
How can an attacker exploit CVE-2018-3996?
An attacker can exploit CVE-2018-3996 by crafting a malicious PDF document designed to trigger the use-after-free condition.
Is there a workaround for CVE-2018-3996?
There is no official workaround for CVE-2018-3996; the best mitigation is to apply the software update.