KLA12530
Multiple vulnerabilities in Foxit Reader

Обновлено: 16/05/2023
Дата обнаружения
09/05/2022
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability can be exploited remotely to execute arbitrary code.
  2. Out of Bounds Read or Use After Free vulnerability in memory access to cause denial of service, execute arbitrary code or obtain sensitive information.
  3. Type Confusion vulnerability in the V8 JavaScript Engine can be exploited to cause denial of service.
  4. Out of Bounds Read vulnerability can be exploited to cause denial of service.
  5. Use After Free vulnerability can be exploited to cause denial of service and execute arbitrary code.
Эксплуатация

The following public exploits exists for this vulnerability:

https://github.com/fastmo/CVE-2022-28672

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Пораженные продукты

Foxit PDF Reader earlier than 11.2.2

Решение

Update to the latest version
Download Foxit Reader

Первичный источник обнаружения
Security updates available in Foxit PDF Reader 11.2.1 and Foxit PDF Editor 11.2.2
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
Foxit Reader
Foxit Reader Enterprise
CVE-IDS
CVE-2022-256415.0Critical
CVE-2022-286795.0Critical
CVE-2022-286715.0Critical
CVE-2022-305575.0Critical
CVE-2022-286695.0Critical
CVE-2022-286765.0Critical
CVE-2022-286825.0Critical
CVE-2022-286745.0Critical
CVE-2022-286735.0Critical
CVE-2022-286815.0Critical
CVE-2022-286835.0Critical
CVE-2022-286725.0Critical
CVE-2022-286775.0Critical
CVE-2022-286755.0Critical
CVE-2022-286785.0Critical
CVE-2022-286705.0Critical
CVE-2022-286805.0Critical
Узнай статистику распространения уязвимостей в твоем регионе