CVE-2017-10952
CVE-2017-10952 Vulnerability Analysis & Exploit Intelligence
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.
Published Updated Sources: cvelistV5, zdi
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Exploit code
public exploit, none observed
EPSS
7%
chance of exploitation in 30 days
CVSS base
Unscored
no source published a base score
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Weakness & attack patterns
- CWE-693
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1574.010Hijack Execution Flow: ServicesFile Permissions Weakness
- T1083File and Directory Discovery
- T1574.005Hijack Execution Flow: Executable Installer File Permissions Weakness
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Indexed by
References
4 on the record
- www.securityfocus.com/bid/100412
vdb-entry, x_refsource_BID
- zerodayinitiative.com/advisories/ZDI-17-692
x_refsource_MISC
- 0patch.blogspot.com/2017/08/0patching-foxit-readers-saveas-0day-cve.html
x_refsource_MISC
- www.securitytracker.com/id/1039212
vdb-entry, x_refsource_SECTRACK
Elsewhere on this site
- zero day initiativeevery CVE for this vendor
- CWE-693other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.