Vulnerability record · CVE-2018-3956 · published 30 January 2019
CVE-2018-3956: Foxit PDF Reader XFA attribute out-of-bounds read
Foxitsoftware · Phantompdf
Foxit Software's PDF Reader 9.1.0.5096 mishandles certain XFA element attributes, causing an out-of-bounds read. A crafted PDF can leak sensitive memory contents, which aids exploitation when chained with another flaw. The record names only version 9.1.0.5096, so other versions cannot be confirmed as affected or fixed from the data given.
Description
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Automated analysis
high priorityHigh CVSS (7.1) with a public exploit reference and very high EPSS percentile, though it requires user interaction and only leaks memory.
What it is
Foxit Software's PDF Reader 9.1.0.5096 mishandles certain XFA element attributes, causing an out-of-bounds read. A crafted PDF can leak sensitive memory contents, which aids exploitation when chained with another flaw. The record names only version 9.1.0.5096, so other versions cannot be confirmed as affected or fixed from the data given.
Impact
An attacker gains disclosure of memory contents from the reader process, which can expose sensitive data and provide information useful for a follow-on exploit. The out-of-bounds read alone does not give code execution.
Attack surface
Reached by opening a malicious PDF, requiring user interaction to trick the victim into opening the file; if the browser plugin extension is enabled, visiting a malicious site can also trigger it. No authentication or privileges are needed (PR:N, UI:R, AV:L).
Exploitation
Not listed in CISA KEV, but EPSS is 0.46008 (98.75th percentile), indicating elevated predicted exploitation activity. Both references are tagged Exploit and Third Party Advisory, so public exploit detail exists.
What to do
- Update Foxit Reader and PhantomPDF to a version later than 9.1.0.5096; the record does not state the fixed version, so confirm with the vendor advisory.
- Disable or remove the browser plugin extension to close the drive-by path.
- Block or sandbox untrusted PDF attachments and downloads at the mail and web gateway.
- Restrict PDF handling to a hardened or isolated viewer for untrusted documents.
- Monitor Foxit vendor advisories for the patched release and track deployment.
Detection
- Hunt for Foxit Reader or PhantomPDF crashes or abnormal exits tied to XFA-heavy PDFs.
- Alert on PDFs containing XFA element attributes from untrusted sources reaching endpoints.
- Correlate process-level memory read anomalies or exploit-protection events in the reader process.
- Track reader version inventory to find hosts still on 9.1.0.5096.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0626 | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0626 | ExploitThird Party Advisory |
Track CVE-2018-3956 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.