CVE-2018-3993 is a critical use-after-free vulnerability in the JavaScript engine of Foxit PDF Reader version 9.2.0.9297 and PhantomPDF, affecting Windows. This vulnerability allows for arbitrary code execution when a user opens a specially crafted PDF document or visits a malicious website if the browser plugin is enabled. Rated 8.8 HIGH on CVSS, it requires user interaction but has low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA KEV, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.2.0.9297CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.