← Vulnerability feed

Vulnerability record · CVE-2018-9958 · published 17 May 2018

CVE-2018-9958: Foxit Reader Text Annotation use-after-free allows code execution

Foxitsoftware · Foxit Reader

Foxit Reader 9.0.1.1049 fails to validate that an object exists before operating on it when setting the point attribute of a Text Annotation, resulting in a use-after-free (CWE-416). A remote attacker can trigger the flaw through a malicious page or file, and successful exploitation runs code in the context of the current process. The record names only version 9.0.1.1049; no other affected versions are stated.

8.8 CVSS 3.0 High EPSS 62% · top 0.8% CWE-416 · Use after free
8.8CVSS 3.0 base score, v2 6.8
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5620.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with no privileges required and high EPSS, though it needs user interaction and is not in KEV.

What it is

Foxit Reader 9.0.1.1049 fails to validate that an object exists before operating on it when setting the point attribute of a Text Annotation, resulting in a use-after-free (CWE-416). A remote attacker can trigger the flaw through a malicious page or file, and successful exploitation runs code in the context of the current process. The record names only version 9.0.1.1049; no other affected versions are stated.

Impact

An attacker gains arbitrary code execution with the privileges of the Foxit Reader process, which can lead to full compromise of the user's session and data.

Attack surface

Reached remotely over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R): the target must visit a malicious page or open a malicious file. The flaw is in Text Annotation handling, specifically the point attribute.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.62922 (99.16th percentile), and public exploit code is referenced on Exploit-DB and Packet Storm. No ransomware group use is documented in the record.

What to do

  • Update Foxit Reader and PhantomPDF to a version later than 9.0.1.1049 per the vendor security bulletins.
  • If immediate patching is not possible, restrict opening of untrusted PDFs and disable or sandbox browser PDF plugins.
  • Block or warn on PDFs from untrusted sources at email and web gateways.
  • Run Foxit Reader with least privilege and enable OS-level exploit mitigations.
  • Monitor vendor bulletins for the fixed build and verify version compliance across endpoints.

Detection

  • Hunt for Foxit Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
  • Monitor for crashes or abnormal termination of Foxit Reader, which can indicate use-after-free exploitation attempts.
  • Alert on PDF files written to temp or user directories that are immediately opened by Foxit Reader.
  • Review endpoint telemetry for Foxit Reader loading unusual DLLs or making unexpected network connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38574Foxitsoftware foxit reader sql injection vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.EPSS 0.99%9.8CVE-2021-38568Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …EPSS 1.1%9.8CVE-2021-38572Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not v…EPSS 1.1%9.8CVE-2021-38573Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not val…EPSS 1.1%9.8CVE-2021-33793Foxitsoftware foxit reader out-of-bounds write vulnerabilityFoxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…EPSS 1.1%9.8CVE-2020-26534Foxitsoftware foxit reader use after free vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…EPSS 2.4%9.8CVE-2020-26535Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable…EPSS 1.7%9.8CVE-2020-26537Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-9958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.