CVE-2024-41605: High severity foxit reader vulnerability
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41605?
CVE-2024-41605 is considered a critical vulnerability due to the potential for remote code execution via a Trojan horse.
How do I fix CVE-2024-41605?
To mitigate CVE-2024-41605, upgrade Foxit PDF Reader or PDF Editor to versions 2024.3 or 13.1.4 or later.
What systems are affected by CVE-2024-41605?
CVE-2024-41605 affects Foxit PDF Reader versions prior to 2024.3 and Foxit PDF Editor versions prior to 2024.3 and 13.1.4.
What kind of attack does CVE-2024-41605 enable?
CVE-2024-41605 allows attackers to exploit the update service to execute arbitrary code by replacing update files with malicious ones.
Is CVE-2024-41605 exploitable remotely?
Yes, CVE-2024-41605 can be exploited remotely by an attacker using the compromised update service to execute their code.