CVE-2022-24356
Published on: Not Yet Published
Last Modified on: 02/28/2022 07:04:00 PM UTC
Certain versions of Macos from Apple contain the following vulnerability:
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the OnMouseExit method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14848.
- CVE-2022-24356 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Foxit - PDF Reader version Foxit reader 11.0.1.0719 macOS
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Bulletins | Foxit | www.foxit.com text/html |
![]() |
ZDI-22-267 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
Related QID Numbers
- 376848 Foxit PDF Reader and Foxit PDF Editor Prior to 11.1.1 for Mac Multiple Security Vulnerabilities
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Macos | - | All | All | All |
Application | Foxit | Pdf Editor | All | All | All | All |
Application | Foxit | Pdf Reader | All | All | All | All |
- cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*:
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*:
- cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*:
Discovery Credit
DoHyun Lee(@l33d0hyun)
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24356 : This vulnerability allows remote attackers to execute arbitrary code on affected installations of… twitter.com/i/web/status/1… | 2022-02-28 19:30:32 |
![]() |
CVE-2022-24356 | 2022-02-28 20:38:47 |