Vulnerability CVE-2023-32664


Published: 2023-07-19

Description:
A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. A specially-crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.

Type:

CWE-843

(Access of Resource Using Incompatible Type ('Type Confusion'))

 References:
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1795
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1795

Copyright 2024, cxsecurity.com

 

Back to Top