Description
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.
In plain language
AI Worth attentionCVE-2017-10952 is a Foxit Reader bug that can let an attacker run code on your computer if you open a specially crafted file or visit a malicious page—if you’re on Foxit Reader 8.2.0.2051, you should act now because a public exploit exists and there’s no known patch.
CVE-2017-10952 is a Foxit Reader flaw (CWE-693/CWE-20) in the saveAs JavaScript handling that can be abused for remote arbitrary code execution when a user interacts by opening a malicious file or visiting a malicious page; it affects Foxit Reader 8.2.0.2051, and a public exploit is available.
What to do now
- Check whether your Foxit Reader version is exactly 8.2.0.2051.
- If you are on Foxit Reader 8.2.0.2051, remove it or replace it with a newer Foxit Reader version (since no patch is available for this CVE).
- Until you update, do not open PDFs or documents from unknown senders, and avoid clicking links from unexpected emails or messages that could lead you to a malicious page.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-10952 and every CVE in our database. Create a free account — no credit card required.
Create Free Account