Foxit Reader BMP BiWidth Heap Buffer Overflow

Strike ID:
E17-3i9h1
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2017

Description

This strike exploits a heap buffer overflow vulnerability in Foxit Reader up version 9.0.1.1049. The vulnerability is due to invalidation of biWidth field when processing BMP file. An attacker could potentially run arbitrary code on the target system by enticing a user to open a maliciously crafted BMP file.

CVE

References

Bid