CVE-2022-37388 is a high-severity vulnerability affecting Foxit PDF Reader 11.2.2.53575 and other Foxit PDF products, allowing remote attackers to execute arbitrary code. The flaw, a read past the end of an allocated buffer (CWE-125) during PDF parsing, requires user interaction, such as opening a malicious file or visiting a malicious page. Successful exploitation could lead to code execution in the context of the current process. Despite its high CVSS score of 7.8, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1.9CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.2.3CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
12.0.0.12394CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:12.0.0.12394:*:*:*:*:*:*:* | ||
< 12.0.1CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.