Kaspersky ID:
KLA60004
Detect Date:
09/12/2023
Updated:
03/06/2024

Description

Multiple vulnerabilities were found in Foxit PDF Reader. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Code execution vulnerability can be exploited remotely to execute arbitrary code.
  2. Use after free vulnerability in Annotation can be exploited to obtain sensitive information.
  3. Out of bounds read vulnerability in AcroForm can be exploited to obtain sensitive information.
  4. Use after free vulnerability in Annotation can be exploited to execute arbitrary code.
  5. Use after free vulnerability in templates can be exploited to obtain sensitive information.
  6. Use after free vulnerability in PDF File Parsing can be exploited to execute arbitrary code.
  7. Out of bounds read vulnerability in XFA Doc Object can be exploited to obtain sensitive information.
  8. Use after free vulnerability in XFA Doc Object can be exploited to execute arbitrary code.
  9. Use after free vulnerability in Doc Object can be exploited to execute arbitrary code.

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Related products

CVE list

  • CVE-2023-39542
    critical
  • CVE-2023-42093
    unknown
  • CVE-2023-42095
    unknown
  • CVE-2023-42094
    unknown
  • CVE-2023-42089
    unknown
  • CVE-2023-42096
    unknown
  • CVE-2023-42090
    unknown
  • CVE-2023-42097
    unknown
  • CVE-2023-42098
    unknown
  • CVE-2023-42091
    unknown
  • CVE-2023-42092
    unknown

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.