CVE-2024-25938
CVE-2024-25938: Use-After-Free in Foxit Reader allows for potential code execution. This vulnerability exists in how Foxit Reader 2024.1.0.23997 processes Barcode widgets. A malicious PDF containing specially crafted JavaScript can trigger the reuse of freed memory, leading to memory corruption and arbitrary code execution. An attacker can exploit this by tricking a user into opening a malicious PDF file or visiting a malicious website if the Foxit Reader browser plugin is enabled. While the CVSS score is 0, SOCRadar's Vulnerability Risk Score (SVRS) is 30. Although this isn't critical, the use-after-free vulnerability can be exploited if a user interacts with malicious content, posing a risk to system integrity. Immediate patching is recommended to mitigate potential threats.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.