NA

CVE-2022-28672

Published: 18/07/2022 Updated: 23/07/2022
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16640.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

foxit pdf_reader

foxit pdf_editor

Github Repositories

Introduction This is my report of CVEs (Common Vulnerabilities and Exposures) while I was in Viettel Cyber Security as an Software Exploitation Intern Detail: This repo include 3 CVEs: CVE-2015-1701: A Win32k LPE vulnerability used in APT attack CVE-2017-5375: JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attack

Foxit PDF Reader Remote Code Execution Exploit

CVE-2022-28672 This bug was Use after Free caused by improper handling of javascript object memory references Blog Foxit PDF Reader - UaF - RCE - JIT Spraying Advisory CVE-2022-28672 Demo

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying

CVE-2022-28672 CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying IOC de omisión de autenticación de FortiOS, FortiProxy y FortiSwitchManager (CVE-2022-40684) Introducción El reciente CVE FortiOS / FortiProxy / FortiSwitchManager ha sido explotado en la naturaleza Nos gustaría proporcionar información adicional sobre la

Introduction This is my report of CVEs (Common Vulnerabilities and Exposures) while I was in Viettel Cyber Security as an Software Exploitation Intern Detail: This repo include 3 CVEs: CVE-2015-1701: A Win32k LPE vulnerability used in APT attack CVE-2017-5375: JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attack

POC Pdf-exploit builder on JavaScript

CVE-2022-28672 This bug was Use after Free caused by improper handling of javascript object memory references Blog Foxit PDF Reader - UaF - RCE - JIT Spraying Advisory CVE-2022-28672 Demo