CVE-2019-6775 is a critical vulnerability affecting Foxit Reader 9.5.0.20723 and PhantomPDF, allowing remote attackers to execute arbitrary code. The flaw, a use-after-free within the exportValues method of AcroForm, stems from insufficient object validation. Successful exploitation requires user interaction, typically opening a malicious file or visiting a malicious page, leading to high impact on confidentiality, integrity, and availability. While rated as high severity (CVSS 7.8), there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.5.0.20723CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* | ||
<= 8.3.10.42705CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.5.0.20723CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.