CVE-2024-25648
CVE-2024-25648 is a use-after-free vulnerability in Foxit Reader that allows for arbitrary code execution. This critical vulnerability occurs when handling a ComboBox widget, allowing a malicious PDF with embedded JavaScript to reuse freed memory. CVE-2024-25648 can be triggered by opening a malicious PDF or visiting a compromised website with the Foxit Reader browser plugin enabled. With an SVRS of 30, this vulnerability indicates a moderate risk, though active monitoring is still advised due to the potential for exploitation. Successful exploitation could lead to arbitrary code execution, enabling an attacker to gain control of the affected system. While the CVSS score is 0, the use-after-free nature of the flaw makes patching extremely important. The impact of this vulnerability is significant, as it can allow for complete system compromise.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.