Haifei Li’s Post

View profile for Haifei Li, graphic

Experienced Vulnerability Researcher & Founder of EXPMON - an Environment-binding Exploit Detection System

The EXPMON Public has reported several Foxit Reader crashes when processing a public PDF sample set. https://lnkd.in/gidnAhMU https://lnkd.in/gCeijxFz https://lnkd.in/grJTxu7b I've manually analyzed them and confirmed they're not zero-day attacks, they're not FPs either. They're even not new Foxit Reader vulns/bugs, as far as I've seen. The crashes could be reproduced in the specific tested Foxit Reader version 2023.2.0.21408 (so not FPs), but not in the latest version. So I'd guess it's a vuln/bug in Foxit Reader just got patched in the last several months. Yeah, sometimes, @EXPMON_ could be used to discover software vulnerabilities (for free), too. You never know what you'd encounter when processing real-world samples! :)

Daniel 🦀 D.

Vulnerability Researcher | Reverse Engineering, Exploit Development & Program Analysis

1mo

I remember Foxit reader was like the goto for learning windows software exploitation, you could fuzz it pretty easily and bugs would fall out, wasn't as many eyes on it as something like Adobe Reader

To view or add a comment, sign in

Explore topics