CVE-2018-3958 is a high-severity use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader (version 9.1.0.5096) and PhantomPDF, affecting Windows. This flaw occurs when accessing the 'Subject' property of the 'this.info' object, potentially leading to arbitrary code execution. Exploitation requires user interaction, either by opening a malicious PDF file or, if the browser plugin is enabled, by visiting a malicious website. While the CVSS score is 7.8 (High), indicating significant impact (confidentiality, integrity, availability), there is no evidence of active exploitation, public exploit code, or KEV listing, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.