hacksysteam / CVE-2022-28672

Foxit PDF Reader Remote Code Execution Exploit
https://hacksys.io/blogs/foxit-reader-uaf-rce-jit-spraying-cve-2022-28672
GNU General Public License v3.0
115 stars 25 forks source link

Could you please provide the POC of this vul and the version of software? #1

Open xupeng1231 opened 1 year ago

xupeng1231 commented 1 year ago

I test this exploit.pdf in foxit pdf reader of version 11.1.0 and 11.2.1, however, neither of these two versions work for this exploitation.

I also prepare a poc by myself, according to your exploitation, but it cannot trigger the vulnerablity or introduce a crash.

So, could you please provide the simplified poc and the testing version of Foxit PDF Reader.

What's more, I download older version Foxit PDF Reader from this website

Thanks.