vendor:
Foxit Reader
by:
Steven Seeley
8.8
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Foxit Reader
Affected Version From: 9.0.1.1049
Affected Version To: 9.0.1.1049
Patch Exists: YES
Related CWE: CVE-2018-9948, CVE-2018-9958
CPE: a:foxitsoftware:foxit_reader
Platforms Tested: Windows 7 Ultimate x86, Windows 10 Pro x86 v1803
2018
Foxit Reader Remote Code Execution Exploit
This exploit allows remote code execution in Foxit Reader. It leverages vulnerabilities CVE-2018-9948 and CVE-2018-9958. The exploit is written in JavaScript and has been tested on Windows 7 Ultimate x86 and Windows 10 Pro x86 v1803. The target version is Foxit Reader v9.0.1.1049. The exploit code can be found at https://srcincite.io/blog/2018/06/22/foxes-among-us-foxit-reader-vulnerability-discovery-and-exploitation.html.
Mitigation:
Update to a patched version of Foxit Reader or use an alternative PDF reader.