CVE-2017-14824 is a critical vulnerability affecting Foxit Reader version 8.3.1.21155, allowing remote code execution due to a type confusion error in the XFAScriptObject insert method. This vulnerability has a CVSS score of 8.8 (High), indicating a severe risk where an attacker can execute arbitrary code with user interaction, such as opening a malicious file or visiting a malicious webpage. Despite its high severity, there is no public exploit code available, nor is it listed on the KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3.1.21155CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:8.3.1.21155:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.