Remote Code Execution Vulnerability in Foxit PDF Reader AcroForms
CVE-2024-12751
Currently unrated
Summary
A vulnerability in Foxit PDF Reader's handling of AcroForms enables remote attackers to execute arbitrary code on affected systems. This flaw arises from inadequate validation of user-supplied data, which can lead to reading beyond the allocated buffer limits. Attackers must entice victims into visiting a compromised webpage or opening a malicious file for successful exploitation. When triggered, this vulnerability allows execution of code within the context of the current process, posing significant risks to data integrity and system security. Interested parties should refer to vendor security bulletins and advisories for the latest updates and mitigation strategies.
Affected Version(s)
PDF Reader 2024.2.3.25184
References
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database