Remote Code Execution Vulnerability in Foxit Reader by Foxit Software
CVE-2018-9966
8.8HIGH
Summary
This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Foxit Reader by exploiting flaws in the handling of Calculate actions for TextBox objects. Exploitation requires user interaction, as targeted victims must open a malicious file or visit a harmful webpage. The root cause of the issue stems from insufficient validation of object existence before operations are performed, potentially enabling attackers to run code within the context of the current process, putting user systems at risk.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved