CVE-2024-9243Disclosure(foxit / pdf_editor)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23932.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_editor
  • pdf_reader

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pdf_editorpdf_reader

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-13: 105-13
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Bullish Times@BullishTimes_
    Disclosure

    Fair challenge — but Project Big Sleep did get a CVE (CVE-2024-9243), and Google published the write-up through Project Zero. The nuance is that it was found in a controlled research setting, not spotted exploiting targets in the wild. Still a first though. The gap between "lab proof of concept" and "weaponised at scale" is shrinking faster than most people are comfortable with. 👀

    Post summary

    Project Big Sleep’s CVE-2024-9243 was disclosed by Google’s Project Zero with a lab proof of concept, but no evidence of real‑world exploitation has been reported.

    1001053
    11.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_editor-macos-
Appfoxitpdf_editor-windows-
Appfoxitpdf_reader-macos-
Appfoxitpdf_reader-windows-

Explore more