CVE-2018-19452 describes a use-after-free vulnerability in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, specifically within the TextBox field Mouse Enter action when processing specially crafted PDF files. This flaw can lead to remote code execution and affects Foxit PDF SDK ActiveX on Windows platforms. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), allowing an attacker to achieve high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.5.0CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:*:*:*:*:professional:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.