Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
CVE-2023-38111

7.8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
3 May 2024

What is CVE-2023-38111?

A vulnerability in Foxit PDF Reader allows attackers to exploit a flaw related to Annotation object handling, leading to the potential execution of arbitrary code in the context of the application. This issue arises due to insufficient validation of object existence before operations are performed. Attackers can leverage this vulnerability by enticing users to visit malicious web pages or open compromised PDF files, which could trigger the exploit. Users of Foxit PDF Reader should remain vigilant and apply any security updates provided by the vendor to mitigate potential risks. For detailed security bulletins, refer to the vendor's advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PDF Reader 12.1.2.15332

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.