CVE-2024-7722 is a Use-After-Free information disclosure vulnerability affecting Foxit PDF Reader and Editor, specifically within the handling of Doc objects. This flaw allows remote attackers to disclose sensitive information due to a lack of object existence validation before operations. Exploitation requires user interaction, typically by opening a malicious file or visiting a malicious page. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a network attack vector with low attack complexity, requiring user interaction, and resulting in low confidentiality impact without affecting integrity or availability. While it can lead to information disclosure, it could be chained with other vulnerabilities for arbitrary code execution. Currently, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness and attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.2.11.54113CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:windows:*:* | ||
>= 12.0.0.12394, < 12.1.8.15703CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:windows:*:* | ||
>= 13.0.0.21632, < 13.1.3.22478CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:windows:*:* | ||
>= 2023.1.0.15510, < 2024.2.3.25184CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:windows:*:* | ||
< 2024.2.3.25184CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.