CVE-2018-9975: Use After Free
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shift events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5762.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9975?
CVE-2018-9975 is categorized as a critical severity vulnerability that allows remote code execution.
How do I fix CVE-2018-9975?
To fix CVE-2018-9975, upgrade to the latest version of Foxit Reader or Foxit PhantomPDF beyond 9.0.1.1049.
What versions are affected by CVE-2018-9975?
CVE-2018-9975 affects Foxit Reader and Foxit PhantomPDF versions up to and including 9.0.1.1049.
Does CVE-2018-9975 require user interaction to be exploited?
Yes, CVE-2018-9975 requires user interaction, as the user must visit a malicious page or open a malicious file.
What type of attacks can be executed through CVE-2018-9975?
CVE-2018-9975 allows remote attackers to execute arbitrary code on vulnerable installations.