• XSS.stack #1 – первый литературный журнал от юзеров форума

Remote CVE-2022-28672 Foxit PDF Reader Doc Object Use-After-Free RCE

propensity

HDD-drive
Пользователь
Регистрация
02.02.2023
Сообщения
40
Реакции
19
Описание:
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.

Возможный POC:

Разбор:
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх