CVE-2016-8856 is a critical vulnerability affecting Foxit Reader for Mac (2.1.0.0804 and earlier) and Foxit Reader for Linux (2.1.0.0805 and earlier). The flaw stems from weak, world-writable file permissions on core installation files, enabling an attacker to overwrite them with malicious code. This could lead to arbitrary code execution, including privilege escalation, with a CVSS score of 7.8 (High). While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.0.0804CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:mac_os_x:*:* | ||
<= 2.1.0.0805CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:linux_kernel:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.