216.73.217.22

CVE-2024-28888

· Published 02/10/2024 21:15 · Modified 08/10/2024 14:14

Labels: CVE-2024-28888 2024-10-02CVE-2024-28888CWE-416[email protected]

Essential information

Published
02/10/2024 21:15
Modified
08/10/2024 14:14
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A use-after-free vulnerability exists in the way Foxit Reade 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
foxit / pdf reader cpe:2.3:a:foxit:pdf_reader:2024.1.0.23997:*:*:*:*:*:*:*

References