Tuesday, November 12, 2024
HomeSecurity NewsMultiple Arbitrary Code Execution Vulnerability in Foxit PDF Reader Affected 9.0.1.1049 and...

Multiple Arbitrary Code Execution Vulnerability in Foxit PDF Reader Affected 9.0.1.1049 and Earlier Versions

Published on

Malware protection

Multiple vulnerabilities reported in the Foxit PDF reader allows an attacker to execute the arbitrary code on the user’s system and obtain sensitive information. The vulnerability affects all the versions of Foxit Reader and Foxit PhantomPDF.

Foxit is the most popular free software for creating, editing and viewing PDF documents. Security researchers from Cisco Talos, Threat Response, Trend Micro’s Zero Day Initiative Foxit PDF Reader vulnerabilities.

CVE-2017-14458 – use-after-free Vulnerability that resides in JavaScript engine of Foxit PDF Reader, attackers could trigger this vulnerability with a specially crafted PDF document.

- Advertisement - SIEM as a Service

CVE-2017-17557 – Heap Buffer Overflow Remote Code Execution vulnerability that may crash the application.

CVE-2018-3842 – Uninitialized pointer vulnerability in the Javascript engine of Foxit PDF Reader that could result in remote code execution.

CVE-2018-3843 – Type confusion vulnerability in the way Foxit reader handles the files with associated extensions.

CVE-2018-3850 – the use-after-free vulnerability that resulting in sensitive memory disclosure or, potentially, arbitrary code execution.

CVE-2018-3853 – use-after-free vulnerability with javascript engine that lies in combinations of the ‘createTemplate’ and ‘closeDoc’ methods.

Also Read Creating and Analyzing a Malicious PDF File with PDF-Parser Tool

Assaf Baharav of Threat Response Research Team Addressed a potential issue where the application could be exposed to Remote Code Execution by abusing GoToE & GoToR Actions.

Ye Yint Min Thu htut Addressed a potential issue where the application could be exposed to Unsafe DLL Loading vulnerability that could be exploited by attackers to execute remote code.

Mitigations – Foxit PDF Reader

Foxit team released an update Foxit Reader and Foxit PhantomPDF. Users are highly recommended to update with new version 9.1 of Foxit Reader and Foxit PhantomPDF.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

VMware Workstation & Fusion Now Available for Free to All Users

VMware has announced that its popular desktop hypervisor products, VMware Workstation and VMware Fusion,...

Dell Enterprise SONiC Flaw Let Attackers Hijack the System

Dell Technologies has disclosed multiple critical security vulnerabilities in its Enterprise SONiC OS, which...

Amazon Confirms Employee Data Breach Via Third-party Vendor

Amazon has confirmed that sensitive employee data was exposed due to a breach at...

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...

Email Header Analysis – Verify Received Email is Genuine or Spoofed

Email Header Analysis highly required process to prevent malicious threats since Email is...