Remote Code Execution Vulnerability in Foxit PDF Reader AcroForms
CVE-2024-12751

Currently unrated

Key Information:

Vendor
Foxit
Status
PDF Reader
Vendor
CVE Published:
30 December 2024

Summary

A vulnerability in Foxit PDF Reader's handling of AcroForms enables remote attackers to execute arbitrary code on affected systems. This flaw arises from inadequate validation of user-supplied data, which can lead to reading beyond the allocated buffer limits. Attackers must entice victims into visiting a compromised webpage or opening a malicious file for successful exploitation. When triggered, this vulnerability allows execution of code within the context of the current process, posing significant risks to data integrity and system security. Interested parties should refer to vendor security bulletins and advisories for the latest updates and mitigation strategies.

Affected Version(s)

PDF Reader 2024.2.3.25184

References

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre Database
.