VYPR
Unrated severityNVD Advisory· Published Dec 18, 2024· Updated Dec 18, 2024

CVE-2024-47810

CVE-2024-47810

Description

A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

Affected products

2
  • Foxit/Foxit Reader Pluginllm-fuzzy2 versions
    = 2024.3.0.26795+ 1 more
    • (no CPE)range: = 2024.3.0.26795
    • (no CPE)range: 2024.3.0.26795

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.