Foxitsoftware Foxit Reader 9.4.1.16828 Remote Code Execution Vulnerability

Summary

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. 

Credit:

The information has been provided by Hui Gao

The original article can be found at: https://www.foxitsoftware.com/support/security-bulletins.php


Details

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of the value property of a Field object within AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Vulnerable Systems:

  • Foxitsoftware Foxit Reader 9.4.1.16828
  • Foxitsoftware Phantompdf 8.3.9.41099
  • Foxitsoftware Phantompdf 9.0.0.29935
  • Foxitsoftware Phantompdf 9.0.1
  • Foxitsoftware Phantompdf 9.0.1.1049
  • Foxitsoftware Phantompdf 9.0.1.31049
  • Foxitsoftware Phantompdf 9.1
  • Foxitsoftware Phantompdf 9.1.0.5096
  • Foxitsoftware Phantompdf 9.2.0.9297
  • Foxitsoftware Phantompdf 9.3
  • Foxitsoftware Phantompdf 9.3.0.10826
  • Foxitsoftware Phantompdf 9.4.0.16811
  • Foxitsoftware Phantompdf 9.4.1.16828

CVE Information:

CVE-2019-6771

Disclosure Timeline:
Publish Date:06/03/2019

Categories: News