A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.
2019-06-17T20:15:09.917
2024-11-21T03:57:56.837
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | foxitsoftware | foxit_pdf_sdk_activex | ≤ 5.5.0 | Yes |
Operating System | microsoft | windows | - | No |