Foxit.Reader.XFA.Forms.Handling.Memory.Corruption

description-logoDescription

This indicates an attack attempt against a Memory Corruption vulnerability in Foxit Reader or PhantomPDF.
The vulnerability is due to an error when the vulnerable software handles a crafted XFA form. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted file. Failed exploits will likely crash the program, leading to a Denial of Service condition.

affected-products-logoAffected Products

Foxit Reader 7.1.3.320
Foxit PhantomPDF 7.1.3.320

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable application.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
http://www.foxitsoftware.com/support/security_bulletins.php

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)