Vulnerability record · CVE-2018-9958 · published 17 May 2018
CVE-2018-9958: Foxit Reader Text Annotation use-after-free allows code execution
Foxitsoftware · Foxit Reader
Foxit Reader 9.0.1.1049 fails to validate that an object exists before operating on it when setting the point attribute of a Text Annotation, resulting in a use-after-free (CWE-416). A remote attacker can trigger the flaw through a malicious page or file, and successful exploitation runs code in the context of the current process. The record names only version 9.0.1.1049; no other affected versions are stated.
Description
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5620.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no privileges required and high EPSS, though it needs user interaction and is not in KEV.
What it is
Foxit Reader 9.0.1.1049 fails to validate that an object exists before operating on it when setting the point attribute of a Text Annotation, resulting in a use-after-free (CWE-416). A remote attacker can trigger the flaw through a malicious page or file, and successful exploitation runs code in the context of the current process. The record names only version 9.0.1.1049; no other affected versions are stated.
Impact
An attacker gains arbitrary code execution with the privileges of the Foxit Reader process, which can lead to full compromise of the user's session and data.
Attack surface
Reached remotely over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R): the target must visit a malicious page or open a malicious file. The flaw is in Text Annotation handling, specifically the point attribute.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.62922 (99.16th percentile), and public exploit code is referenced on Exploit-DB and Packet Storm. No ransomware group use is documented in the record.
What to do
- Update Foxit Reader and PhantomPDF to a version later than 9.0.1.1049 per the vendor security bulletins.
- If immediate patching is not possible, restrict opening of untrusted PDFs and disable or sandbox browser PDF plugins.
- Block or warn on PDFs from untrusted sources at email and web gateways.
- Run Foxit Reader with least privilege and enable OS-level exploit mitigations.
- Monitor vendor bulletins for the fixed build and verify version compliance across endpoints.
Detection
- Hunt for Foxit Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Monitor for crashes or abnormal termination of Foxit Reader, which can indicate use-after-free exploitation attempts.
- Alert on PDF files written to temp or user directories that are immediately opened by Foxit Reader.
- Review endpoint telemetry for Foxit Reader loading unusual DLLs or making unexpected network connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160240/Foxit-Reader-9.0.1.1049-Arbitrary-Code-Execution.html | |
| https://www.exploit-db.com/exploits/44941/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45269/ | Third Party AdvisoryVDB Entry |
| https://www.foxitsoftware.com/support/security-bulletins.php | PatchVendor Advisory |
| https://zerodayinitiative.com/advisories/ZDI-18-342 | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/160240/Foxit-Reader-9.0.1.1049-Arbitrary-Code-Execution.html | |
| https://www.exploit-db.com/exploits/44941/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45269/ | Third Party AdvisoryVDB Entry |
| https://www.foxitsoftware.com/support/security-bulletins.php | PatchVendor Advisory |
| https://zerodayinitiative.com/advisories/ZDI-18-342 | Third Party AdvisoryVDB Entry |
Track CVE-2018-9958 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-9958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.