CVE-2018-3946 is a high-severity use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader version 9.1.0.5096 and PhantomPDF. This flaw allows an attacker to achieve arbitrary code execution by tricking a user into opening a specially crafted PDF document or visiting a malicious website if the browser plugin is enabled. With a CVSS score of 8.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, its community discussion and media coverage indicate some awareness. The EPSS score suggests a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.