CVE-2016-8856
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.
Foxit Reader para Mac 2.1.0.0804 y versiones anteriores y Foxit Reader para Linux 2.1.0.0805 y versiones anteriores sufrieron una vulnerabilidad donde permisos de archivo débiles podrían ser explotados por atacantes para ejecutar código arbitrario. Después de la instalación, archivos del núcleo de Foxit Reader eran de escritura universal por defecto, permitiendo a un atacante sobre escribirlos con código de puerta trasera, lo cual cuando se ejecuta por un usuario privilegiado resultará en Privilege Escalation, Code Execution o ambas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-19 CVE Reserved
- 2016-10-31 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-275: Permission Issues
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93608 | Technical Description | |
http://www.securitytracker.com/id/1037101 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.foxitsoftware.com/support/security-bulletins.php | 2017-07-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Foxitsoftware Search vendor "Foxitsoftware" | Reader Search vendor "Foxitsoftware" for product "Reader" | <= 2.1.0.0804 Search vendor "Foxitsoftware" for product "Reader" and version " <= 2.1.0.0804" | mac_os_x |
Affected
| ||||||
Foxitsoftware Search vendor "Foxitsoftware" | Reader Search vendor "Foxitsoftware" for product "Reader" | <= 2.1.0.0805 Search vendor "Foxitsoftware" for product "Reader" and version " <= 2.1.0.0805" | linux_kernel |
Affected
|