CVE-2018-14442
CRITICALFoxit Reader <9.2 - PhantomPDF <9.2 - Use After Free
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-14442. PoCs published by payatu, sandi-go.
AI-analyzed exploit summary This repository contains a working exploit for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader's CPDF_Parser::m_pCryptoHandler. The exploit leverages heap spraying and a ROP chain to achieve remote code execution by embedding malicious JavaScript in a crafted PDF.
Description
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Exploits (2)
This repository contains a working exploit for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader's CPDF_Parser::m_pCryptoHandler. The exploit leverages heap spraying and a ROP chain to achieve remote code execution by embedding malicious JavaScript in a crafted PDF.
This repository contains a writeup for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader and PhantomPDF. The flaw exists in the handling of CPDF_Parser::m_pCryptoHandler, allowing remote code execution when a user opens a malicious file.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H