CVE-2023-27379
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jul 19, 2023
Updated: Jul 26, 2023
CWE ID 416
Summary
CVE-2023-27379 is a use-after-free vulnerability affecting Foxit Software's PDF Reader version 12.1.2.15332. This issue arises due to the untimely deletion of objects linked to PDF pages. A maliciously crafted PDF document can exploit this vulnerability by causing the JavaScript engine to reuse previously freed memory, potentially resulting in arbitrary code execution. To exploit the vulnerability, an attacker requires the user to open the malicious file or visit a specially designed, malicious website, assuming the browser plugin extension is enabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Foxit Software Inc.