CVE-2022-24971
Published on: Not Yet Published
Last Modified on: 03/01/2022 01:23:00 PM UTC
Certain versions of Pdf Editor from Foxit contain the following vulnerability:
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15812.
- CVE-2022-24971 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Foxit - PDF Reader version 11.1.0.52543
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Bulletins | Foxit | www.foxit.com text/html |
![]() |
ZDI-22-319 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Foxit | Pdf Editor | All | All | All | All |
Application | Foxit | Pdf Editor | All | All | All | All |
Application | Foxit | Pdf Reader | All | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*:
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*:
- cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
Discovery Credit
Anonymous
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24971 : This vulnerability allows remote attackers to execute arbitrary code on affected installations of… twitter.com/i/web/status/1… | 2022-02-28 20:54:36 |