Vulnerability record · CVE-2018-9948 · published 17 May 2018
CVE-2018-9948: Foxit Reader and PhantomPDF uninitialized pointer leaks memory
Foxitsoftware · Foxit Reader
Foxit Reader 9.0.0.29935 (and PhantomPDF) mishandles typed arrays, accessing a pointer that was never properly initialized. This lets a remote attacker disclose sensitive information from the process, and the leak can be chained with other bugs to achieve code execution.
Description
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of typed arrays. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5380.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh EPSS and public exploit code make this memory-disclosure bug a practical stepping stone to code execution, despite the medium CVSS score.
What it is
Foxit Reader 9.0.0.29935 (and PhantomPDF) mishandles typed arrays, accessing a pointer that was never properly initialized. This lets a remote attacker disclose sensitive information from the process, and the leak can be chained with other bugs to achieve code execution.
Impact
An attacker gains disclosure of sensitive memory contents from the victim's process, which can defeat ASLR and supply the primitives needed for follow-on code execution in the context of the current process.
Attack surface
Reached over the network by convincing the target to visit a malicious page or open a malicious PDF; no authentication is required, but user interaction is required per the CVSS vector (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.637, 99.2nd percentile) and public Exploit-DB entries exist, indicating exploit code is available.
What to do
- Update Foxit Reader and PhantomPDF to a version past 9.0.0.29935 per the vendor security bulletins.
- Block or sandbox untrusted PDF handling and disable JavaScript in the PDF reader where possible.
- Enforce email and web filtering to reduce delivery of malicious PDFs and links.
- If patching is delayed, restrict or remove the reader from high-value endpoints and use an alternate viewer.
Detection
- Monitor for Foxit Reader or PhantomPDF spawning unexpected child processes or making anomalous network connections.
- Hunt for PDF files matching known Exploit-DB PoC characteristics (44941, 45269) in email and download telemetry.
- Alert on crashes or memory-access faults in Foxit Reader processes, which can indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/44941/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45269/ | Third Party AdvisoryVDB Entry |
| https://www.foxitsoftware.com/support/security-bulletins.php | PatchVendor Advisory |
| https://zerodayinitiative.com/advisories/ZDI-18-332 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44941/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45269/ | Third Party AdvisoryVDB Entry |
| https://www.foxitsoftware.com/support/security-bulletins.php | PatchVendor Advisory |
| https://zerodayinitiative.com/advisories/ZDI-18-332 | Third Party AdvisoryVDB Entry |
Track CVE-2018-9948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-9948), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.