CVE-2018-3850 is a use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader version 9.0.1.1049. It allows arbitrary code execution when a user opens a specially crafted PDF or visits a malicious website if the browser plugin is enabled. This vulnerability has a CVSS score of 8.8 (HIGH), indicating a network-based attack with low complexity, requiring user interaction, and leading to high impact on confidentiality, integrity, and availability. While no public exploit code is available via Metasploit, Nuclei, or ExploitDB, the vulnerability has received some community discussion and media coverage. It is not currently listed on the CISA KEV catalog or Hot List, suggesting it is not under active widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_reader:9.0.1.1049:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.