vendor:
Foxit Reader
by:
Manoj Ahuje
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Foxit Reader
Affected Version From: 9.0.1.1049
Affected Version To: 9.0.1.1049
Patch Exists: YES
Related CWE:
CPE: a:foxitsoftware:foxit_reader:9.0.1.1049
Platforms Tested: Windows 7 Pro (x32)
2018
Foxit Reader 9.0.1.1049 – Buffer Overflow (ASLR)(DEP)
This exploit makes use of heap space to store the shellcode and bypasses ASLR and DEP to execute the payload successfully.
Mitigation:
Update to a patched version of Foxit Reader.