CVE-2024-7724

Description

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23900.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.273

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 2024 (EXE) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 2024 (ML) (EXE) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 2024 (ML) (MSI) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 2024 (MSI) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 13 (13.1.3.22478)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Editor 13 (MSI) (13.1.3.22478)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 13 (13.1.4.23147)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 12 (EXE) (12.1.8.15703)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 12 (ML) (EXE) (12.1.8.15703)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 12 (ML) (MSI) (12.1.8.15703)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 12 (MSI) (12.1.8.15703)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (EXE) (11.2.11.54113)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (EXE) (11.2.11.54113)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (MSI) (11.2.11.54113)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (MSI) (11.2.11.54113)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Reader (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit PDF Reader (ML) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit Reader Enterprise (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725 are fixed in Foxit Reader Enterprise (ML) (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725,CVE-2024-29072 are fixed in Foxit PDF Editor 13 (13.1.3.22478)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725,CVE-2024-29072 are fixed in Foxit PDF Editor 13 (MSI) (13.1.3.22478)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 12 (EXE) (12.1.6.15509)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725,CVE-2024-29072 are fixed in Foxit PDF Reader (2024.2.3.25184)Windows
Vulnerabilities CVE-2024-7722,CVE-2024-7723,CVE-2024-7724,CVE-2024-7725,CVE-2024-29072 are fixed in Foxit PDF Editor 2024 (EXE) (2024.2.3.25184)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-340413Foxit PDF Editor 2024 (EXE) (2024.2.3.25184)
PATCH-340416Foxit PDF Editor 2024 (ML) (EXE) (2024.2.3.25184)
PATCH-340417Foxit PDF Editor 2024 (ML) (MSI) (2024.2.3.25184)
PATCH-340418Foxit PDF Editor 2024 (MSI) (2024.2.3.25184)
PATCH-340414Foxit PDF Editor 13 (13.1.3.22478)
PATCH-340415Foxit PDF Editor 13 (MSI) (13.1.3.22478)
PATCH-341790Foxit PDF Editor 13 (13.1.4.23147)
PATCH-341840Foxit PDF Editor 12 (EXE) (12.1.8.15703)
PATCH-341841Foxit PDF Editor 12 (ML) (EXE) (12.1.8.15703)
PATCH-341842Foxit PDF Editor 12 (ML) (MSI) (12.1.8.15703)
PATCH-341843Foxit PDF Editor 12 (MSI) (12.1.8.15703)
PATCH-342372Foxit PDF Editor 11 (EXE) (11.2.11.54113)
PATCH-342373Foxit PDF Editor 11 (ML) (EXE) (11.2.11.54113)
PATCH-342374Foxit PDF Editor 11 (ML) (MSI) (11.2.11.54113)
PATCH-342375Foxit PDF Editor 11 (MSI) (11.2.11.54113)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347387Foxit Reader (ML) (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)
PATCH-347384Foxit PDF Reader (ML) (MSI) (2025.1.0.27937)
PATCH-347380Foxit PDF Editor 13 (13.1.7.23637)
PATCH-347383Foxit PDF Editor 13 (MSI) (13.1.7.23637)
PATCH-343985Foxit PDF Editor 12 (EXE) (12.1.9.15762)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-344499Foxit PDF Editor 2024 (EXE) (2024.4.1.27687)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234