CVE-2017-14837 is a critical type confusion vulnerability in Foxit Reader versions 8.3.1.21155 and earlier, specifically within the pageSpan method of XFA Layout objects. This flaw allows remote attackers to execute arbitrary code on a user's system if they open a malicious file or visit a malicious web page. Rated with a CVSS score of 8.8 (High), exploitation requires user interaction but can lead to full compromise of the affected process. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential impact remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3.1.21155CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:8.3.1.21155:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.