Remote Code Execution Vulnerability in Foxit PDF Reader AcroForms
CVE-2024-30355

7.8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
2 April 2024

What is CVE-2024-30355?

The vulnerability pertains to a flaw in the handling of Doc objects within AcroForms in Foxit PDF Reader. This security issue stems from insufficient validation of user-supplied data, resulting in a potential write operation exceeding the allocated memory buffer. Consequently, an attacker may exploit this vulnerability by enticing the user to access a compromised webpage or open a maliciously crafted file, which can lead to arbitrary code execution within the current process context. User interaction is essential for this attack vector, highlighting the need for users to be vigilant against untrusted sources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PDF Reader 2023.3.0.23028

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.