CVE-2024-41605

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 284

Summary

CVE-2024-41605 is a vulnerability affecting Foxit PDF Reader before 2024.3 and PDF Editor before 2024.3, as well as older versions of the 13.x series (before 13.1.4). An attacker can exploit this issue by replacing a legitimate update file with a malicious one during the side loading process. Since the update service fails to validate the updater's integrity, attacker-controlled code can be executed, potentially leading to security compromise. Users are advised to apply the available patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share