Remote Code Execution Vulnerability after Foxit Reader is released (CVE-2017-10945)
Remote Code Execution Vulnerability after Foxit Reader is released (CVE-2017-10945)
Release date:
Updated on:
Affected Systems:
Foxit Reader 8.3.0.14878
Description:
Bugtraq id: 102808
CVE (CAN) ID: CVE-2017-10945
Foxit Reader is a small PDF document viewer and print program.
Foxit Reader 8.3.0.14878 has a security vulnerability in app. alert function implementation. Attackers can exploit this vulnerability to execute arbitrary code in the context of the current process.
<* Source: Steven Seeley (mr_me)
*>
Suggestion:
Vendor patch:
Foxit
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.foxitsoftware.com
Https://www.foxitsoftware.com/support/security-bulletins.php
Http://zerodayinitiative.com/advisories/ZDI-17-458/