SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-3843

An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations.

HIGH 8.8EPSS 23.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 23.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. A specially crafted PDF document can lead to an object of invalid type to be dereferenced, which can potentially lead to sensitive memory disclosure, and possibly to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
23.59% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-704
Affected
foxitsoftware/foxit reader
Source
talos-cna@cisco.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.