CVE-2018-17610: Foxitsoftware Phantompdf

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

Affected products

Published 2018-09-28. Last modified 2026-06-17.