CVE-2015-8843

HIGH

Foxit Reader 6.1-6.2.x and 7.x < 7.2.2 - Privilege Escalation via Shared Memory Corruption

Title source: llm
STIX 2.1

Description

The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.foxitsoftware.com/support/security-bulletins.php#FRD-35
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-640

Scores

CVSS v3 7.4
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (10)
foxitsoftware/foxit_reader 6.1
foxitsoftware/foxit_reader 6.1.2
foxitsoftware/foxit_reader 6.1.4
foxitsoftware/foxit_reader 6.2
foxitsoftware/foxit_reader 6.2.1
foxitsoftware/foxit_reader 7.0
foxitsoftware/foxit_reader 7.0.1
foxitsoftware/foxit_reader 7.0.6
foxitsoftware/foxit_reader 7.1.5
foxitsoftware/foxit_reader 7.2
Published Apr 13, 2016
Tracked Since Feb 18, 2026