Remote Code Execution Vulnerability in Foxit PDF Reader Due to U3D File Parsing
CVE-2024-30349
What is CVE-2024-30349?
The vulnerability in Foxit PDF Reader is associated with the improper validation of user-supplied data during the parsing of U3D files. This flaw can lead to an out-of-bounds write, which allows a remote attacker to execute arbitrary code on the affected system. Successful exploitation requires user interaction; the target must either open a malicious file or visit a harmful webpage. This situation widens the attack surface, as users may inadvertently expose themselves to risk through common actions. The flaw can potentially allow unauthorized commands to be executed in the context of the current process, emphasizing the need for immediate remedial actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PDF Reader 2023.3.0.23028
References
CVSS V3.1
Timeline
Vulnerability published