KLA11093
Arbitrary code execution vulnerabilities in Foxit Reader
Updated: 11/09/2017
CVSS
?
6.8
Detect date
?
08/17/2017
Severity
?
High
Description

Multiple serious vulnerabilities have been found in Foxit Reader and Foxit PhantomPDF. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An improper validation of user-supplied data in the saveAs Java script function can be exploited remotely via a specially designed page or file to execute arbitrary code;
  2. An improper validation of a user-supplied string before using it to execute a system call in the app.launchURL method can be exploited remotely via a specially designed page or file to execute arbitrary code. 
  3. An improper validation vulnerability can be exploited remotely to execute arbitrary code.

NB: These vulnerabilities do not have any public CVSS ratings, so rating can be changed by the time.

Affected products

Foxit Reader versions through 8.3.1.21155

Solution

Update to the latest version
Download Foxit Reader
Download Foxit PhantomPDF

Original advisories

ZDI-17-691
ZDI-17-718
ZDI-17-692

Impacts
?
ACE 
[?]
Related products
Foxit Reader
Foxit Phantom PDF
CVE-IDS
?

CVE-2017-10953
CVE-2017-10952
CVE-2017-10951