Foxit Reader Use-After-Free Remote Code Execution Vulnerability

Rocco Calvi

ZDI ID: ZDI-16-027
ZDI-CAN: ZDI-CAN-3470
CVSS
6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Vendors
Foxit
Affected Products
Foxit Reader

Additional Details

Disclosure Timeline

  • 2015-12-17 — Vulnerability reported to vendor
  • 2016-01-25 — Coordinated public release of advisory