CVE-2017-7584

Description

Memory Corruption Vulnerability in Foxit PDF Toolkit before 2.1 allows an attacker to cause Denial of Service & Remote Code Execution when a victim opens a specially crafted PDF file.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.287

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader (8.3.0.14878)Windows
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader Enterprise (8.3.0.14878)Windows
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader (8.3.1.21155)Windows
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader Enterprise (8.3.1.21155)Windows
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader (8.3.2.25013)Windows
Vulnerabilities CVE-2017-7584 are fixed in Update For Foxit Reader Enterprise (8.3.2.25013)Windows
Vulnerabilities CVE-2017-7584 are fixed in Foxit PhantomPDF 10 (EXE) (10.1.8.37795)Windows
Vulnerabilities CVE-2017-7584 are fixed in Foxit PhantomPDF 10 (MSI) (10.1.8.37795)Windows
Vulnerabilities CVE-2017-7584 are fixed in Foxit PhantomPDF 10 (ML) (EXE) (10.1.8.37795)Windows
Vulnerabilities CVE-2017-7584 are fixed in Foxit PhantomPDF 10 (ML) (MSI) (10.1.8.37795)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-331212Foxit PhantomPDF 10 (EXE) (10.1.12.37872)
PATCH-331215Foxit PhantomPDF 10 (MSI) (10.1.12.37872)
PATCH-331213Foxit PhantomPDF 10 (ML) (EXE) (10.1.12.37872)
PATCH-331214Foxit PhantomPDF 10 (ML) (MSI) (10.1.12.37872)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234