CVE-2024-25648

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 30, 2024
CWE ID 416

Summary

The CVE-2024-25648 vulnerability affects Foxit Reader 2024.1.0.23997 and can be exploited through a ComboBox widget. By tricking the user into opening a malicious PDF document or visiting a specially crafted website with the browser plugin enabled, an attacker can trigger a use-after-free vulnerability, leading to memory corruption and potential arbitrary code execution. The risk score is high, with a base severity of 8.8 and impact on integrity and confidentiality being high as well. The exploitability score is 2.8, indicating that it is moderately difficult to exploit. No remediation steps are provided in the information provided, but users should ensure they are using the latest version of Foxit Reader and exercise caution when opening files from untrusted sources to mitigate the potential danger this vulnerability poses to their organization's security.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-25648 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions