CVE-2019-5126: Use After Free
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5126?
CVE-2019-5126 has a critical severity rating as it allows for arbitrary code execution through a use-after-free condition.
How do I fix CVE-2019-5126?
To mitigate CVE-2019-5126, users should update to the latest version of Foxit PDF Reader or Foxit PhantomPDF after version 9.7.0.29435.
Who is affected by CVE-2019-5126?
CVE-2019-5126 affects users of Foxit Reader and Foxit PhantomPDF versions up to 9.7.0.29435.
What type of vulnerability is CVE-2019-5126?
CVE-2019-5126 is classified as a use-after-free vulnerability in the JavaScript engine.
What exploit can occur due to CVE-2019-5126?
CVE-2019-5126 can be exploited by tricking a user into opening a specially crafted PDF, leading to arbitrary code execution.