CVE-2019-17140 is a remote code execution vulnerability affecting Foxit PhantomPDF version 9.6.0.25114. This flaw, stemming from improper handling of the OnFocus event, allows an attacker to execute arbitrary code on a user's system if they open a malicious file or visit a malicious web page. Rated with a CVSS score of 8.8 (High), it requires user interaction but can lead to full compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.6.0.25114CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:9.6.0.25114:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.