668
VMScore

CVE-2018-14442

Published: 20/07/2018 Updated: 17/09/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Foxit Reader prior to 9.2 and PhantomPDF prior to 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

foxitsoftware phantompdf

foxitsoftware foxit reader

Github Repositories

Foxit Reader - CPDF_Parser::m_pCryptoHandler - Use After Free - RCE Vulnerability Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code Vulnerability Description This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader User interaction is required to exploit this v