← Vulnerability feed

Vulnerability record · CVE-2018-9948 · published 17 May 2018

CVE-2018-9948: Foxit Reader and PhantomPDF uninitialized pointer leaks memory

Foxitsoftware · Foxit Reader

Foxit Reader 9.0.0.29935 (and PhantomPDF) mishandles typed arrays, accessing a pointer that was never properly initialized. This lets a remote attacker disclose sensitive information from the process, and the leak can be chained with other bugs to achieve code execution.

6.5 CVSS 3.0 Medium EPSS 63% · top 0.8% CWE-824 · CWE-824CWE-200 · Information exposure
6.5CVSS 3.0 base score, v2 4.3
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of typed arrays. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5380.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityHigh EPSS and public exploit code make this memory-disclosure bug a practical stepping stone to code execution, despite the medium CVSS score.

What it is

Foxit Reader 9.0.0.29935 (and PhantomPDF) mishandles typed arrays, accessing a pointer that was never properly initialized. This lets a remote attacker disclose sensitive information from the process, and the leak can be chained with other bugs to achieve code execution.

Impact

An attacker gains disclosure of sensitive memory contents from the victim's process, which can defeat ASLR and supply the primitives needed for follow-on code execution in the context of the current process.

Attack surface

Reached over the network by convincing the target to visit a malicious page or open a malicious PDF; no authentication is required, but user interaction is required per the CVSS vector (UI:R).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.637, 99.2nd percentile) and public Exploit-DB entries exist, indicating exploit code is available.

What to do

  • Update Foxit Reader and PhantomPDF to a version past 9.0.0.29935 per the vendor security bulletins.
  • Block or sandbox untrusted PDF handling and disable JavaScript in the PDF reader where possible.
  • Enforce email and web filtering to reduce delivery of malicious PDFs and links.
  • If patching is delayed, restrict or remove the reader from high-value endpoints and use an alternate viewer.

Detection

  • Monitor for Foxit Reader or PhantomPDF spawning unexpected child processes or making anomalous network connections.
  • Hunt for PDF files matching known Exploit-DB PoC characteristics (44941, 45269) in email and download telemetry.
  • Alert on crashes or memory-access faults in Foxit Reader processes, which can indicate exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38574Foxitsoftware foxit reader sql injection vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.EPSS 0.99%9.8CVE-2021-38568Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …EPSS 1.1%9.8CVE-2021-38572Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not v…EPSS 1.1%9.8CVE-2021-38573Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not val…EPSS 1.1%9.8CVE-2021-33793Foxitsoftware foxit reader out-of-bounds write vulnerabilityFoxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…EPSS 1.1%9.8CVE-2020-26534Foxitsoftware foxit reader use after free vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…EPSS 2.4%9.8CVE-2020-26535Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable…EPSS 1.7%9.8CVE-2020-26537Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-9948), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.