CVE-2018-3967 is a critical use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader (version 9.1.0.5096) and PhantomPDF, affecting Windows platforms. This flaw allows an attacker to execute arbitrary code by tricking a user into opening a specially crafted PDF document or visiting a malicious website if the browser plugin is enabled. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, its high EPSS and FAUCET Risk Score indicate a substantial potential for future exploitation, and it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.