Foxit Reader 2.3 before Build 3902 and 3.0 before Build...
Vulnerability Description
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0836
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/501623/100/0/threaded
- http://secunia.com/advisories/34036
- http://lists.immunitysec.com/pipermail/dailydave/2010-April/006079.html
- http://www.vupen.com/english/advisories/2009/0634
- http://www.securitytracker.com/id?1021824
- http://www.securityfocus.com/bid/34035
- http://blog.zoller.lu/2009/03/remote-code-execution-in-pdf-still.html
- http://www.coresecurity.com/content/foxit-reader-vulnerabilities
- http://www.foxitsoftware.com/pdf/reader/security.htm#bypass
More from foxitsoftware
View All →Affected Vendor
foxitsoftware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.