Security readout for executives and security teams
Plain-English summary
CVE-2018-10479 is an information disclosure flaw in Foxit Reader 9.0.0.29935. A user would need to open a malicious file or visit a malicious page. The bug can expose sensitive process memory and may help an attacker when chained with other vulnerabilities.
Executive priority
Handle as a desktop application remediation item with moderate urgency. It is not described as remotely exploitable without user action, but PDF readers are common phishing targets and the bug may strengthen a chained attack.
Technical view
The flaw is a CWE-125 out-of-bounds read in Foxit Reader U3D Key Frame structure parsing. The source describes insufficient validation of user-supplied data, causing reads past an allocated structure. ZDI tracked it as ZDI-CAN-5399 / ZDI-18-389.
Likely exposure
Exposure is limited to systems running Foxit Reader 9.0.0.29935, especially users who receive untrusted PDFs or browse to attacker-controlled content. The bundle does not identify other affected versions or products.
Exploitation context
The source states exploitation requires user interaction. CISA KEV is false, and the bundle provides no evidence of active exploitation. The issue may support code execution only when combined with other vulnerabilities.
Researcher notes
Evidence is incomplete for scoring and remediation specifics: the bundle has no CVSS vector, no affected CPEs, and no explicit fixed version. Validation should stay version-based and source-grounded unless Foxit guidance adds more detail.
Mitigation direction
- Inventory Foxit Reader installations and identify version 9.0.0.29935.
- Check Foxit security bulletins for vendor-approved fixed builds or guidance.
- Upgrade or replace affected Foxit Reader installations where vendor guidance supports it.
- Limit opening of untrusted PDFs and links until affected systems are remediated.
Validation and detection
- Confirm endpoint software inventory includes Foxit Reader version details.
- Flag any host running Foxit Reader 9.0.0.29935.
- Review email and web controls for handling of untrusted PDF content.
- Verify remediation by rechecking installed Foxit Reader versions after updates.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2018-10479 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.foxitsoftware.com/support/security-bulletins.phpCVE reference · x_refsource_CONFIRM
- https://zerodayinitiative.com/advisories/ZDI-18-389CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
