CVE-2018-9939 is a remote code execution vulnerability affecting Foxit Reader 9.0.0.29935 and PhantomPDF, stemming from a type confusion error in layout element handling due to insufficient user data validation. This high-severity vulnerability (CVSS 8.8) requires user interaction, such as opening a malicious file, to achieve full impact (confidentiality, integrity, and availability). While no active exploitation, public exploit code (Metasploit, ExploitDB), or significant community discussion has been observed, its potential for arbitrary code execution under the current process context makes it a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | ||
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.