CVE-2020-8844 is a critical integer overflow vulnerability affecting Foxit Reader and PhantomPDF versions 9.6.0.25114 and earlier. This flaw, residing in the JPEG parsing component during PDF conversion, allows remote attackers to execute arbitrary code with user interaction, typically by opening a malicious file. With a CVSS score of 7.8 (High), successful exploitation grants an attacker full control over the affected system. While no public exploits, Metasploit modules, or active exploitation have been identified, the vulnerability's high FAUCET Risk Score of 91/100 indicates significant potential impact. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.7.0.29478CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* | ||
<= 9.7.0.29455CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.