Cyber Resilience

CVE-2022-37332

HighPublic PoC

Published: 21 November 2022

Published
21 November 2022
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.1549 94.8th percentile
Risk Priority 25 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-37332 is a high-severity Use After Free (CWE-416) vulnerability in Foxit Pdf Reader. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 5.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader version 12.0.1.12430. The flaw is triggered when a specially crafted PDF document misuses the media player API, causing reuse of previously freed memory that can result in arbitrary code execution. The issue is tracked as CWE-416 and carries a CVSS 3.1 score of 7.8.

An attacker can exploit the vulnerability by convincing a user to open a malicious PDF file. Exploitation is also possible if a user visits a malicious site while the browser plugin extension remains enabled, allowing the same code-execution outcome without direct file handling.

The referenced Talos reports provide the primary technical details on the flaw but do not include explicit mitigation guidance in the supplied information. The EPSS score has remained flat at 0.1549 with no material increase since disclosure.

EU & UK References

Vulnerability details

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An…

more

attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

foxit
pdf reader
12.0.1.12430

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-416

Use-after-free exploits that achieve arbitrary code execution are blocked or significantly hardened by non-executable pages and ASLR.

References