Skip to main content

Foxit Releases Security Updates Affecting Foxit PDF Reader and Foxit PDF Editor

Security updates address multiple vulnerabilities that could lead to remote code execution, information disclosure, privilege escalation, or DoS

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address multiple vulnerabilities that could lead to remote code execution, information disclosure, privilege escalation, or DoS


Threat details

Proof-of-concept for CVE-2024-49576 and CVE-2024-47810

Proof-of-concept exploit code has been published for CVE-2024-49576 and CVE-2024-47810. NHS England National CSOC assesses exploitation as more likely.


Introduction

Foxit has released security updates to address multiple vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, as well as corresponding updates for Foxit PDF Editor for Mac and Foxit PDF Reader for Mac.

The most concerning vulnerabilities are use-after-free vulnerabilities known as CVE-2024-49576 and CVE-2024-47810 that could allow an attacker to achieve remote code execution (RCE). Other vulnerabilities address information disclosure, privilege escalation, denial-of-service (DoS), and DLL hijacking, which could allow attackers the ability to execute arbitrary code, extract NTLM hashes, or access sensitive information.


Remediation advice

Affected organisations are encouraged to review the following Foxit Security Bulletins (Release date December 17, 2024) and apply the relevant updates.   



Last edited: 19 December 2024 1:14 pm