CVE-2024-30331 is a use-after-free vulnerability in Foxit PDF Reader's AcroForm handling, specifically affecting the Doc objects, and also impacts Apple and Microsoft products. This high-severity flaw (CVSS 7.8) allows remote attackers to achieve arbitrary code execution if a user opens a malicious file or visits a malicious page. While user interaction is required, successful exploitation grants an attacker full control within the current process. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.6.0109CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 12.0.0.0601, < 12.1.2.55366CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 13.0.0.61829, < 13.0.1.61866CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2023.1.0.55583, < 2023.3.0.63083CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
< 2023.3.0.63083CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.