Foxit Reader Annotation delay Use-After-Free

Strike ID:
E18-5niq1
CVSS:
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2018

Description

A use-after-free vulnerability exists in Foxit Reader. The specific flaw resides within the handling of the delay property for 'Annotation' objects. Successful exploitation may result in execution of arbitrary code with user privileges. Failure to exploit will not typically result in a crash.

CVE

Metasploit

Zdi