CVE-2017-14834 is a high-severity arbitrary code execution vulnerability affecting Foxit Reader version 8.3.1.21155. It stems from insufficient validation of FileAttachment annotation objects, allowing remote attackers to execute code in the context of the current process. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious webpage. The vulnerability has a CVSS v3 score of 8.8 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation (KEV: No), nor are there public exploits available in Metasploit or ExploitDB. Community discussion and media coverage for CVE-2017-14834 are minimal, with no mentions or articles reported. This suggests a low level of public awareness or attention, despite the potential for significant impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3.1.21155CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:8.3.1.21155:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.