CVE-2018-3964 is a use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader (version 9.1.0.5096) and PhantomPDF, affecting Windows. A specially crafted PDF document can lead to arbitrary code execution by reusing a freed memory object. This vulnerability has a high CVSS score of 7.8, indicating a significant risk, as it requires user interaction (opening a malicious file or visiting a malicious site if the browser plugin is enabled) but can result in high confidentiality, integrity, and availability impacts. While there is no known active exploitation, public exploit code, or KEV listing, it has garnered some community discussion and media coverage, suggesting awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.