First published: Tue Mar 05 2024(Updated: )
In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit Reader | <2024.1 | |
Foxit PhantomPDF for Windows | <2024.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25858 has been assessed as a high severity vulnerability due to the potential for code execution via JavaScript.
To mitigate CVE-2024-25858, users should update to Foxit PDF Reader or PDF Editor version 2024.1 or later.
CVE-2024-25858 affects Foxit PDF Reader versions before 2024.1 and Foxit PDF Editor versions before 2024.1.
Exploitation of CVE-2024-25858 could allow an attacker to execute arbitrary code on the user's system via unoptimized JavaScript prompts.
Using Foxit PDF Reader or Editor versions before 2024.1 poses a security risk due to CVE-2024-25858, and it is advised to update immediately.