Vulnerability Description
A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Pdf Reader | 12.1.2.15332 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1795ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1795ExploitThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1795
FAQ
What is CVE-2023-32664?
CVE-2023-32664 is a vulnerability with a CVSS score of 8.8 (HIGH). A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause mem...
How severe is CVE-2023-32664?
CVE-2023-32664 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32664?
Check the references section above for vendor advisories and patch information. Affected products include: Foxit Pdf Reader.