Remote Code Execution Vulnerability in Foxit PDF Reader's AcroForm Handling
CVE-2024-12752

7.8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
30 December 2024

What is CVE-2024-12752?

A vulnerability exists within Foxit PDF Reader related to the handling of AcroForms, wherein insufficient validation of user-supplied data can lead to memory corruption. This flaw enables remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, as it necessitates the opening of a malicious file or visiting a harmful web page. Severity of impact arises from the potential execution of code within the context of the current process, posing serious security risks to users.

Affected Version(s)

PDF Reader 2024.2.3.25184

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.