CVE-2018-14442
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
- Affected products
- Foxit Reader, Phantompdf
- Foxitsoftware Foxit Reader
- < 9.2
- Foxitsoftware Phantompdf
- < 9.2
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 4.7% (91th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2018-07-20
CVE-2018-14442 at NVD
2 known exploits for CVE-2018-14442
Proof-of-concept code and exploit modules indexed by Sploitus