Use-After-Free Vulnerability in Foxit PDF Reader Software
CVE-2018-3942
8HIGH
What is CVE-2018-3942?
An exploitable use-after-free vulnerability is present in the JavaScript engine of Foxit PDF Reader. This flaw arises when a specific PDF is manipulated to interact with a previously freed object in memory, leading to the potential execution of arbitrary code. An attacker can leverage this vulnerability by deceiving the user into opening a specially crafted PDF document. Ensuring users are aware of the risks associated with untrusted files is essential to mitigating this threat.
Affected Version(s)
Foxit PDF Reader 9.1.0.5096