Vulnerability Description
Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f.".
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxitsoftware | Foxit Reader | 8.3.2.25013 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101009Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040038
- https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-14694Third Party Advisory
- https://www.foxitsoftware.com/support/security-bulletins.php
- http://www.securityfocus.com/bid/101009Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040038
- https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-14694Third Party Advisory
- https://www.foxitsoftware.com/support/security-bulletins.php
FAQ
What is CVE-2017-14694?
CVE-2017-14694 is a vulnerability with a CVSS score of 7.8 (HIGH). Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute arbitrary code or cause a denial of service via a c...
How severe is CVE-2017-14694?
CVE-2017-14694 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14694?
Check the references section above for vendor advisories and patch information. Affected products include: Foxitsoftware Foxit Reader.