Use-After-Free Vulnerability in Foxit Reader Could Lead to Arbitrary Code Execution
CVE-2024-25648
What is CVE-2024-25648?
A use-after-free vulnerability has been identified in Foxit Reader 2024.1.0.23997, specifically affecting the handling of ComboBox widgets. This vulnerability is exploited through specially crafted JavaScript code embedded in malicious PDF documents. When a user inadvertently opens such a file, the vulnerability can trigger the reuse of previously freed memory objects, leading to memory corruption. As a result, this may allow attackers to execute arbitrary code, posing significant risks to affected users. Furthermore, exploitation can occur if users visit malicious websites while the browser plugin for Foxit Reader is enabled, further expanding the attack surface.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Foxit Reader 2024.1.0.23997