CVE-2018-14442

CRITICAL

Foxit Reader <9.2 - PhantomPDF <9.2 - Use After Free

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-14442. PoCs published by payatu, sandi-go.

AI-analyzed exploit summary This repository contains a working exploit for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader's CPDF_Parser::m_pCryptoHandler. The exploit leverages heap spraying and a ROP chain to achieve remote code execution by embedding malicious JavaScript in a crafted PDF.

Description

Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.

Exploits (2)

nomisec WORKING POC 58 stars
by payatu · poc
https://github.com/payatu/CVE-2018-14442

This repository contains a working exploit for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader's CPDF_Parser::m_pCryptoHandler. The exploit leverages heap spraying and a ROP chain to achieve remote code execution by embedding malicious JavaScript in a crafted PDF.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Foxit Reader 9.0.1.1049 x86
No auth needed
Prerequisites: Foxit Reader 9.0.1.1049 x86 on Windows 7 Enterprise Build 7601 SP1 x86 · Heap in a specific state for successful exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by sandi-go · poc
https://github.com/sandi-go/PS-2018-002---CVE-2018-14442

This repository contains a writeup for CVE-2018-14442, a use-after-free vulnerability in Foxit Reader and PhantomPDF. The flaw exists in the handling of CPDF_Parser::m_pCryptoHandler, allowing remote code execution when a user opens a malicious file.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Foxit Reader 9.0.1.1049 and prior, Foxit PhantomPDF 9.0.1.1049 and prior
No auth needed
Prerequisites: User interaction to open a malicious file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0474
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (2)
foxitsoftware/foxit_reader < 9.2
foxitsoftware/phantompdf < 9.2
Published Jul 20, 2018
Tracked Since Feb 18, 2026