Last active
December 21, 2025 01:18
-
-
Save 003random/780da665cfd623c527ba759d0285192e to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| { | |
| "schema": "attack_flow_v2", | |
| "theme": "dark_theme", | |
| "objects": [ | |
| { | |
| "id": "flow", | |
| "instance": "34b905d2-8943-4243-a78c-d6d8de28b586", | |
| "properties": [ | |
| [ | |
| "name", | |
| "CVE-2024-25575" | |
| ], | |
| [ | |
| "description", | |
| "Foxit Reader 2024.1.0.23997 mishandles a Lock object, allowing a crafted PDF to corrupt memory and grant arbitrary code-execution." | |
| ], | |
| [ | |
| "author", | |
| [ | |
| [ | |
| "name", | |
| "Volerion" | |
| ], | |
| [ | |
| "identity_class", | |
| null | |
| ], | |
| [ | |
| "contact_information", | |
| "contact@volerion.com" | |
| ] | |
| ] | |
| ], | |
| [ | |
| "scope", | |
| "incident" | |
| ], | |
| [ | |
| "external_references", | |
| [] | |
| ], | |
| [ | |
| "created", | |
| { | |
| "time": "2025-07-26T01:55:25.669+02:00", | |
| "zone": "Europe/Amsterdam" | |
| } | |
| ] | |
| ], | |
| "objects": [ | |
| "df34c01c-f976-483f-86cc-89421bc72b24", | |
| "80a2e1aa-7690-4e5a-87d7-1081d7396277", | |
| "05283896-fbe3-4178-acc4-0a8ae6988a47", | |
| "6a166a61-0280-46e4-8744-d10f00ca66fd", | |
| "3bdccafa-f35d-42ff-92d0-bd4c09f5c165", | |
| "58b9d724-2c5f-4177-a964-a7598e0e7118", | |
| "6bc8f627-7ec7-42cf-bb33-7b10bed516af", | |
| "6fd3fea3-2e3e-4ee6-957b-fd55815cded7", | |
| "bdc590c3-c9b2-4597-8497-3388f41093fc", | |
| "f511ee47-6273-4416-96a2-a7d8a9af9125", | |
| "6de19982-013b-4f4a-abeb-ce87fa5cfc68", | |
| "a65c7223-531f-41d7-bf9e-cb1ecf5f472f", | |
| "42db24c5-e538-40c2-afe6-526b60bff84f", | |
| "886325eb-81c4-435a-a1cc-4b4d93490346", | |
| "e378a546-11e0-41f2-b342-5fc0c797b62d", | |
| "f21cce3d-ed65-43f4-887f-16ef7eda36ce", | |
| "ecee2a62-cc85-4aa3-8458-40204386d8d7", | |
| "3624bf53-a351-4e3c-82d1-ebe73f5f26e8", | |
| "a80e3520-96ae-45b9-bb3f-09148df0def5", | |
| "ccdb9aa7-2c06-4e4a-b482-b1843bb26b2a", | |
| "dc4bfffd-3898-46de-b155-1fb1f9d73273", | |
| "901ff3f2-dc79-4889-b681-4761b76e7417", | |
| "4c979aea-f5c9-498d-b216-236b6ecdc92a", | |
| "ece290ee-cbb2-4796-9298-9d3ae05c0b69" | |
| ] | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "df34c01c-f976-483f-86cc-89421bc72b24", | |
| "source": "ba12b6c2-ce8d-4a32-a9ee-f53c67de34d6", | |
| "target": "10e279c8-5074-4931-9701-b8b4fbff819b", | |
| "handles": [ | |
| "baca3e5e-21ba-4e22-a1f4-1ecd460a6fd6" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "ba12b6c2-ce8d-4a32-a9ee-f53c67de34d6" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "10e279c8-5074-4931-9701-b8b4fbff819b" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "baca3e5e-21ba-4e22-a1f4-1ecd460a6fd6" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "80a2e1aa-7690-4e5a-87d7-1081d7396277", | |
| "source": "00baa737-4d23-42fe-9a97-566965de757c", | |
| "target": "1f736ace-24a2-4cdc-aa47-2ff06adcc690", | |
| "handles": [ | |
| "dc16a464-c18f-40a0-8c0c-e007b1630614" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "00baa737-4d23-42fe-9a97-566965de757c" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "1f736ace-24a2-4cdc-aa47-2ff06adcc690" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "dc16a464-c18f-40a0-8c0c-e007b1630614" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "05283896-fbe3-4178-acc4-0a8ae6988a47", | |
| "source": "2e2cdae5-a1d6-4675-9bbf-21b613fdbce7", | |
| "target": "4f7416e3-2a4e-4084-9dae-94f6fdc11b83", | |
| "handles": [ | |
| "6b28def4-5406-4c6a-8eb0-fa05cc870585" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "2e2cdae5-a1d6-4675-9bbf-21b613fdbce7" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "4f7416e3-2a4e-4084-9dae-94f6fdc11b83" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "6b28def4-5406-4c6a-8eb0-fa05cc870585" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "6a166a61-0280-46e4-8744-d10f00ca66fd", | |
| "source": "1c16cd7b-7570-49f1-ac4b-0275422b3fe0", | |
| "target": "930d1c79-4fa7-4b94-89f5-293548d1ff94", | |
| "handles": [ | |
| "7f7fd757-a8b0-49d5-9235-21947e6cf261" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "1c16cd7b-7570-49f1-ac4b-0275422b3fe0" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "930d1c79-4fa7-4b94-89f5-293548d1ff94" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "7f7fd757-a8b0-49d5-9235-21947e6cf261" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "3bdccafa-f35d-42ff-92d0-bd4c09f5c165", | |
| "source": "a51a71b8-fbd7-4d2b-bd66-5118dd8a3466", | |
| "target": "4d4af2f6-762a-4715-b9e7-46e1dda80836", | |
| "handles": [ | |
| "93b97d93-bfd4-4e33-8de4-cbcc74dd6263" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "a51a71b8-fbd7-4d2b-bd66-5118dd8a3466" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "4d4af2f6-762a-4715-b9e7-46e1dda80836" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "93b97d93-bfd4-4e33-8de4-cbcc74dd6263" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "58b9d724-2c5f-4177-a964-a7598e0e7118", | |
| "source": "0c7d9471-d814-432f-9e14-93736865fe9b", | |
| "target": "f24b70d0-724d-4d45-a951-eb9bde86a8a2", | |
| "handles": [ | |
| "6b4ff26a-df4c-442f-b2e2-ad66a91256ae" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "0c7d9471-d814-432f-9e14-93736865fe9b" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "f24b70d0-724d-4d45-a951-eb9bde86a8a2" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "6b4ff26a-df4c-442f-b2e2-ad66a91256ae" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "6bc8f627-7ec7-42cf-bb33-7b10bed516af", | |
| "source": "a4f530f9-062d-41ac-a2b0-804166213f2b", | |
| "target": "9dc61b7f-31c4-4311-8a18-5176440175c4", | |
| "handles": [ | |
| "90b2c570-a0c3-4ad5-9d81-e79b79a324c6" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "a4f530f9-062d-41ac-a2b0-804166213f2b" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "9dc61b7f-31c4-4311-8a18-5176440175c4" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "90b2c570-a0c3-4ad5-9d81-e79b79a324c6" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "6fd3fea3-2e3e-4ee6-957b-fd55815cded7", | |
| "source": "575ddb3b-a9a6-42da-a23c-c52eb3bbce7f", | |
| "target": "5e750bcd-7e95-4c61-b72f-75e56e27e043", | |
| "handles": [ | |
| "66244e5d-fe28-4868-8ca8-5888b7426b15" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "575ddb3b-a9a6-42da-a23c-c52eb3bbce7f" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "5e750bcd-7e95-4c61-b72f-75e56e27e043" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "66244e5d-fe28-4868-8ca8-5888b7426b15" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "bdc590c3-c9b2-4597-8497-3388f41093fc", | |
| "source": "d787da4e-1974-4926-8f70-1e533f9c42d5", | |
| "target": "a1805e26-a812-4e5b-8e64-9cff65a99149", | |
| "handles": [ | |
| "e1aee0f0-fe1b-4a71-bb58-f804f1c45c7e" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "d787da4e-1974-4926-8f70-1e533f9c42d5" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "a1805e26-a812-4e5b-8e64-9cff65a99149" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "e1aee0f0-fe1b-4a71-bb58-f804f1c45c7e" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "f511ee47-6273-4416-96a2-a7d8a9af9125", | |
| "source": "6d9a70f3-fa09-442e-8074-fd9005434bd1", | |
| "target": "5dda4c76-88c3-4ff6-864e-3771164e2f3f", | |
| "handles": [ | |
| "dadffb7a-d4a0-4695-8c98-2862ece6c081" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "6d9a70f3-fa09-442e-8074-fd9005434bd1" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "5dda4c76-88c3-4ff6-864e-3771164e2f3f" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "dadffb7a-d4a0-4695-8c98-2862ece6c081" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "6de19982-013b-4f4a-abeb-ce87fa5cfc68", | |
| "source": "ae00dfce-0fd2-4e67-98a8-ce800880db8a", | |
| "target": "34b29a1f-50c6-4081-b505-4d8589543cc6", | |
| "handles": [ | |
| "9e7eed0b-66f6-4020-9b52-3b86cdb91f67" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "ae00dfce-0fd2-4e67-98a8-ce800880db8a" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "34b29a1f-50c6-4081-b505-4d8589543cc6" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "9e7eed0b-66f6-4020-9b52-3b86cdb91f67" | |
| }, | |
| { | |
| "id": "dynamic_line", | |
| "instance": "a65c7223-531f-41d7-bf9e-cb1ecf5f472f", | |
| "source": "75065683-d733-47d2-a956-36b30879d6c0", | |
| "target": "33516144-de86-459b-8376-2e980c40ad5c", | |
| "handles": [ | |
| "f554526c-7ae1-4357-ba77-71530dd226ff" | |
| ] | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "75065683-d733-47d2-a956-36b30879d6c0" | |
| }, | |
| { | |
| "id": "generic_latch", | |
| "instance": "33516144-de86-459b-8376-2e980c40ad5c" | |
| }, | |
| { | |
| "id": "generic_handle", | |
| "instance": "f554526c-7ae1-4357-ba77-71530dd226ff" | |
| }, | |
| { | |
| "id": "vulnerability", | |
| "instance": "42db24c5-e538-40c2-afe6-526b60bff84f", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Type Confusion in Foxit Reader Lock Object" | |
| ], | |
| [ | |
| "description", | |
| "Foxit Reader 2024.1.0.23997 mishandles a Lock object, allowing a crafted PDF to corrupt memory and grant arbitrary code-execution." | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "ee63c145-606a-4b2c-9d35-dc6488957376", | |
| "30": "279ada6a-5803-45ec-a182-fe9b8fc04401", | |
| "60": "0847d9a1-a639-4f7a-912f-60317a1435fe", | |
| "90": "ad40b7a2-60c3-4cc6-b3f6-f5bcc2668f58", | |
| "120": "51b07df4-4604-4684-a779-c9630f246799", | |
| "150": "9be7ceea-d8d0-4df1-a040-3dcac3e41a08", | |
| "180": "da708214-0cf0-4d25-bff8-29a68e106880", | |
| "210": "a8fb2643-a4a7-4d9e-9b9e-3bd877a6cd45", | |
| "240": "0e82b780-49fc-4213-9968-57af53d04899", | |
| "270": "0ffe93a3-b641-4e04-a615-258c5cfccc4a", | |
| "300": "b42273b9-a1a4-41b8-8e2e-a3689934fb74", | |
| "330": "184b26ee-2d8f-4add-b0a2-23d953f8cd96" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "ee63c145-606a-4b2c-9d35-dc6488957376", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "279ada6a-5803-45ec-a182-fe9b8fc04401", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "0847d9a1-a639-4f7a-912f-60317a1435fe", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ad40b7a2-60c3-4cc6-b3f6-f5bcc2668f58", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "51b07df4-4604-4684-a779-c9630f246799", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "9be7ceea-d8d0-4df1-a040-3dcac3e41a08", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "da708214-0cf0-4d25-bff8-29a68e106880", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "a8fb2643-a4a7-4d9e-9b9e-3bd877a6cd45", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "0e82b780-49fc-4213-9968-57af53d04899", | |
| "latches": [ | |
| "2e2cdae5-a1d6-4675-9bbf-21b613fdbce7" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "0ffe93a3-b641-4e04-a615-258c5cfccc4a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "b42273b9-a1a4-41b8-8e2e-a3689934fb74", | |
| "latches": [ | |
| "a51a71b8-fbd7-4d2b-bd66-5118dd8a3466" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "184b26ee-2d8f-4add-b0a2-23d953f8cd96", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "886325eb-81c4-435a-a1cc-4b4d93490346", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Deliver Malicious PDF to Victim" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "The attacker sends a specially crafted PDF that contains hostile JavaScript to the victim via e-mail, file sharing, or another delivery channel.\n\nsource: attacker\nproximity: remote\nphase: delivery" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "14e0244d-2282-428c-a051-0c22900ce815", | |
| "30": "304eb847-5fd2-4e05-b632-e4304b6c482d", | |
| "60": "34ff6ff8-1cf6-4cbd-b745-326161dbdd28", | |
| "90": "07748947-1469-4c49-9059-39998774a5ac", | |
| "120": "a82ee99c-f2b3-4432-ad34-2974a37ff0b9", | |
| "150": "0ef5c955-6206-4e97-a534-4a4b06a86fbd", | |
| "180": "057c325d-1007-4a53-82b6-ced6aea6c2ce", | |
| "210": "101ab57b-a167-4d12-997d-1461977dd96d", | |
| "240": "054a2b63-1a9b-44dd-83e1-3bded532f164", | |
| "270": "a9d680e4-e0c0-4d79-b09f-2fcbff3a4d8d", | |
| "300": "d4a01b17-d504-49fc-8464-c38c6dee278a", | |
| "330": "afba4ae0-dafe-435b-9085-050b19ff3e2a" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "14e0244d-2282-428c-a051-0c22900ce815", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "304eb847-5fd2-4e05-b632-e4304b6c482d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "34ff6ff8-1cf6-4cbd-b745-326161dbdd28", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "07748947-1469-4c49-9059-39998774a5ac", | |
| "latches": [ | |
| "4f7416e3-2a4e-4084-9dae-94f6fdc11b83" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "a82ee99c-f2b3-4432-ad34-2974a37ff0b9", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "0ef5c955-6206-4e97-a534-4a4b06a86fbd", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "057c325d-1007-4a53-82b6-ced6aea6c2ce", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "101ab57b-a167-4d12-997d-1461977dd96d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "054a2b63-1a9b-44dd-83e1-3bded532f164", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "a9d680e4-e0c0-4d79-b09f-2fcbff3a4d8d", | |
| "latches": [ | |
| "0c7d9471-d814-432f-9e14-93736865fe9b" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "d4a01b17-d504-49fc-8464-c38c6dee278a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "afba4ae0-dafe-435b-9085-050b19ff3e2a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "e378a546-11e0-41f2-b342-5fc0c797b62d", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Victim Opens PDF in Foxit Reader Desktop" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "The user opens the received PDF with the Foxit Reader desktop application.\n\nsource: user\nproximity: local\nparticipation: active\nphase: delivery" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "1fe0ce8e-2643-437d-be06-b7e351d2f627", | |
| "30": "11ca2ac4-4872-40e9-b0aa-3bbe0368bfe6", | |
| "60": "80bc10e2-244e-4824-bbe7-6c6d9da465cc", | |
| "90": "1d5080e8-1484-4227-9453-0d767b8a693e", | |
| "120": "6c06272f-0844-4a87-a595-accf2687e9aa", | |
| "150": "54d54419-19e0-4405-8379-903f2b438570", | |
| "180": "67ec4aa0-e39a-4180-89c6-a553991f8d81", | |
| "210": "13a63370-3d90-46db-b1af-85598a6a00d8", | |
| "240": "6b0b540c-53f4-43d7-97f4-aa858e3cab19", | |
| "270": "f40df501-9381-4469-8e67-d803a8cbd688", | |
| "300": "6929c8cd-2df9-41cc-bd1f-29ff74d3717f", | |
| "330": "ebc25756-863b-440b-a9be-05ec0314c141" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "1fe0ce8e-2643-437d-be06-b7e351d2f627", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "11ca2ac4-4872-40e9-b0aa-3bbe0368bfe6", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "80bc10e2-244e-4824-bbe7-6c6d9da465cc", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "1d5080e8-1484-4227-9453-0d767b8a693e", | |
| "latches": [ | |
| "f24b70d0-724d-4d45-a951-eb9bde86a8a2" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "6c06272f-0844-4a87-a595-accf2687e9aa", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "54d54419-19e0-4405-8379-903f2b438570", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "67ec4aa0-e39a-4180-89c6-a553991f8d81", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "13a63370-3d90-46db-b1af-85598a6a00d8", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "6b0b540c-53f4-43d7-97f4-aa858e3cab19", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "f40df501-9381-4469-8e67-d803a8cbd688", | |
| "latches": [ | |
| "00baa737-4d23-42fe-9a97-566965de757c" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "6929c8cd-2df9-41cc-bd1f-29ff74d3717f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "ebc25756-863b-440b-a9be-05ec0314c141", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "f21cce3d-ed65-43f4-887f-16ef7eda36ce", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Execute Embedded JavaScript" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "Foxit Reader — either the desktop application or the browser plugin — processes and executes the embedded JavaScript contained in the PDF.\n\nsource: system\nphase: exploitation" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "b5333cce-693b-44ab-b284-818fffb473b8", | |
| "30": "c1ac8503-29ad-4c9d-bfe2-e2b556446bcb", | |
| "60": "4dee2ff1-2a25-4312-a0c8-257afcedcfb4", | |
| "90": "08118485-257c-47bf-aa99-f8edce2a18eb", | |
| "120": "36989af6-4256-4b99-a1f6-97b5a5105e5b", | |
| "150": "748c713c-7a3a-4787-961c-00a701421acc", | |
| "180": "fc8b942d-3334-4214-bbf8-0c0e096e2ce0", | |
| "210": "476ef532-5c94-4a09-9a11-6e055641cf95", | |
| "240": "ba4d2c40-0167-491f-8913-594c2561290e", | |
| "270": "ef69ec9f-000a-4931-b717-cc832a94ef85", | |
| "300": "722d3fe8-8885-4a45-8a4a-4e85fb412a17", | |
| "330": "94880284-262d-4204-83aa-8941288af0b4" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "b5333cce-693b-44ab-b284-818fffb473b8", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "c1ac8503-29ad-4c9d-bfe2-e2b556446bcb", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "4dee2ff1-2a25-4312-a0c8-257afcedcfb4", | |
| "latches": [ | |
| "10e279c8-5074-4931-9701-b8b4fbff819b" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "08118485-257c-47bf-aa99-f8edce2a18eb", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "36989af6-4256-4b99-a1f6-97b5a5105e5b", | |
| "latches": [ | |
| "1f736ace-24a2-4cdc-aa47-2ff06adcc690" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "748c713c-7a3a-4787-961c-00a701421acc", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "fc8b942d-3334-4214-bbf8-0c0e096e2ce0", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "476ef532-5c94-4a09-9a11-6e055641cf95", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ba4d2c40-0167-491f-8913-594c2561290e", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ef69ec9f-000a-4931-b717-cc832a94ef85", | |
| "latches": [ | |
| "575ddb3b-a9a6-42da-a23c-c52eb3bbce7f" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "722d3fe8-8885-4a45-8a4a-4e85fb412a17", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "94880284-262d-4204-83aa-8941288af0b4", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "ecee2a62-cc85-4aa3-8458-40204386d8d7", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Victim Visits Attacker-Controlled URL" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "The user navigates to an attacker-controlled URL in a web browser that has the Foxit Reader plugin enabled.\n\nsource: user\nproximity: local\nparticipation: passive\nphase: delivery" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "5967def4-6832-4149-8491-24983ad363b4", | |
| "30": "a9400695-61f5-4b87-b4cd-a1d938f0ccb7", | |
| "60": "865c830c-9c43-4f39-8acb-3190373e8d46", | |
| "90": "47f31b0f-0128-4ff8-865d-fe6f085af365", | |
| "120": "ee9efad0-c7f1-4788-b204-878bcd69a1e9", | |
| "150": "1644d447-62c1-4c9c-8022-c4b4cd7df0f8", | |
| "180": "55b1a752-36a1-4e49-9796-3d1fa6931754", | |
| "210": "17654de9-85a0-44ca-984f-30674bfcf3f7", | |
| "240": "4f86dd2e-d4e7-4dd5-bbf9-942c61cdbf0b", | |
| "270": "2d6105a0-db02-4400-9ba3-ac65e8bd7cc6", | |
| "300": "232bb230-449c-412e-8b59-837f30892e37", | |
| "330": "872c61ce-6138-4826-94cb-e5008be28be8" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "5967def4-6832-4149-8491-24983ad363b4", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "a9400695-61f5-4b87-b4cd-a1d938f0ccb7", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "865c830c-9c43-4f39-8acb-3190373e8d46", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "47f31b0f-0128-4ff8-865d-fe6f085af365", | |
| "latches": [ | |
| "930d1c79-4fa7-4b94-89f5-293548d1ff94" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ee9efad0-c7f1-4788-b204-878bcd69a1e9", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "1644d447-62c1-4c9c-8022-c4b4cd7df0f8", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "55b1a752-36a1-4e49-9796-3d1fa6931754", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "17654de9-85a0-44ca-984f-30674bfcf3f7", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "4f86dd2e-d4e7-4dd5-bbf9-942c61cdbf0b", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "2d6105a0-db02-4400-9ba3-ac65e8bd7cc6", | |
| "latches": [ | |
| "a4f530f9-062d-41ac-a2b0-804166213f2b" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "232bb230-449c-412e-8b59-837f30892e37", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "872c61ce-6138-4826-94cb-e5008be28be8", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "3624bf53-a351-4e3c-82d1-ebe73f5f26e8", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Attacker Serves Malicious PDF Over HTTP" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "The attacker’s web server responds with the weaponized PDF, sending it to the victim’s browser for rendering.\n\nsource: attacker\nproximity: remote\nphase: delivery" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "45c28ba4-c00c-4d85-9ef1-3444e2888b24", | |
| "30": "8cb4f58f-aa45-4c0a-bea6-8d7afa1b150c", | |
| "60": "ff6d9333-827f-489f-94ce-2efd4c26d450", | |
| "90": "2a42ac9a-58ed-4f65-96e7-d65e3a595d9f", | |
| "120": "90267e34-39d2-46fa-ad8b-d1e091110d12", | |
| "150": "baf85cd9-f3ee-416f-bcdb-aece911e1db0", | |
| "180": "f2a7e9b4-2fa4-48d9-8bbe-245339704e92", | |
| "210": "bc9ee666-0857-4627-92f8-dfdeee6de57a", | |
| "240": "7ef88fab-c731-4ad8-a7b2-ad714d6d7e25", | |
| "270": "a37cccac-eb0f-431a-9913-aba9f20b05cb", | |
| "300": "01662180-ecf3-44e3-8dbe-decd365c2773", | |
| "330": "a194a7e5-9387-4d71-9b11-45da1069e475" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "45c28ba4-c00c-4d85-9ef1-3444e2888b24", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "8cb4f58f-aa45-4c0a-bea6-8d7afa1b150c", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ff6d9333-827f-489f-94ce-2efd4c26d450", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "2a42ac9a-58ed-4f65-96e7-d65e3a595d9f", | |
| "latches": [ | |
| "9dc61b7f-31c4-4311-8a18-5176440175c4" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "90267e34-39d2-46fa-ad8b-d1e091110d12", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "baf85cd9-f3ee-416f-bcdb-aece911e1db0", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "f2a7e9b4-2fa4-48d9-8bbe-245339704e92", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "bc9ee666-0857-4627-92f8-dfdeee6de57a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "7ef88fab-c731-4ad8-a7b2-ad714d6d7e25", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "a37cccac-eb0f-431a-9913-aba9f20b05cb", | |
| "latches": [ | |
| "ba12b6c2-ce8d-4a32-a9ee-f53c67de34d6" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "01662180-ecf3-44e3-8dbe-decd365c2773", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "a194a7e5-9387-4d71-9b11-45da1069e475", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "condition", | |
| "instance": "a80e3520-96ae-45b9-bb3f-09148df0def5", | |
| "properties": [ | |
| [ | |
| "description", | |
| "Foxit Reader Browser Plugin Installed and Enabled (environment)" | |
| ], | |
| [ | |
| "pattern", | |
| null | |
| ], | |
| [ | |
| "pattern_type", | |
| null | |
| ], | |
| [ | |
| "pattern_version", | |
| null | |
| ], | |
| [ | |
| "date", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "4517c291-32dd-4433-8f9d-4f8e87baefb2", | |
| "30": "b31877a6-fbd7-44c5-ad6b-75b10f3cf30d", | |
| "60": "2e02ada1-4ed5-4c7a-9baa-ff4fef8a3b81", | |
| "90": "3ffe2ab4-7b97-4cf4-9a48-884708bfb393", | |
| "120": "faf4045d-fc75-43ac-aea4-a8c8f20d8861", | |
| "150": "3b1d3fbb-c81f-41cb-bcc6-90dd50d63bc7", | |
| "180": "c6d0e768-b1c0-450f-b73d-78c7eeab3357", | |
| "210": "2c87b281-eca3-4dbb-8f91-b4bea7ca3fa1", | |
| "330": "20d7e1a4-c6f9-460d-bf3a-05f9dca1192a", | |
| "branch:True": "1aa61cc0-db3b-4f14-8955-87a608be8ed9", | |
| "branch:False": "323ccff5-726a-4da3-93c1-0f9a60de7e66" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "4517c291-32dd-4433-8f9d-4f8e87baefb2", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "b31877a6-fbd7-44c5-ad6b-75b10f3cf30d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "2e02ada1-4ed5-4c7a-9baa-ff4fef8a3b81", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "3ffe2ab4-7b97-4cf4-9a48-884708bfb393", | |
| "latches": [ | |
| "4d4af2f6-762a-4715-b9e7-46e1dda80836" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "faf4045d-fc75-43ac-aea4-a8c8f20d8861", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "3b1d3fbb-c81f-41cb-bcc6-90dd50d63bc7", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "c6d0e768-b1c0-450f-b73d-78c7eeab3357", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "2c87b281-eca3-4dbb-8f91-b4bea7ca3fa1", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "20d7e1a4-c6f9-460d-bf3a-05f9dca1192a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "1aa61cc0-db3b-4f14-8955-87a608be8ed9", | |
| "latches": [ | |
| "1c16cd7b-7570-49f1-ac4b-0275422b3fe0" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "323ccff5-726a-4da3-93c1-0f9a60de7e66", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "action", | |
| "instance": "ccdb9aa7-2c06-4e4a-b482-b1843bb26b2a", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Type Confusion Triggers Memory Corruption and Code Execution" | |
| ], | |
| [ | |
| "ttp", | |
| [ | |
| [ | |
| "tactic", | |
| null | |
| ], | |
| [ | |
| "technique", | |
| null | |
| ] | |
| ] | |
| ], | |
| [ | |
| "description", | |
| "A type-confused operation is performed on the Lock object, corrupting memory and granting the attacker arbitrary code-execution in the victim's context.\n\nsource: system\nphase: exploitation" | |
| ], | |
| [ | |
| "confidence", | |
| null | |
| ], | |
| [ | |
| "execution_start", | |
| null | |
| ], | |
| [ | |
| "execution_end", | |
| null | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "4934d1f9-ea9d-4df3-88d4-97e1598edbb8", | |
| "30": "49a96b55-774f-4c49-a319-cc1840b97c9d", | |
| "60": "08cc915e-55f7-4ebd-ae6f-a409b244194d", | |
| "90": "40b9fead-8f80-4584-bad8-d5de4b720fb5", | |
| "120": "361e2ac9-4f89-4e23-b653-e2a9ccdd10a5", | |
| "150": "0eb53495-f311-49ce-8191-135b63eae21f", | |
| "180": "4a06d705-ea97-4a3a-be01-0e6541f75c12", | |
| "210": "3e3a4073-dd88-4fe2-8957-3ec047b73a95", | |
| "240": "1a4ee6d0-ae5e-4b6c-9916-b7dd0a2ff168", | |
| "270": "2f09eca2-8d78-45cb-bbb0-c688f9d6d452", | |
| "300": "c8e9032c-4eda-4c70-b594-7afb147ea830", | |
| "330": "75e5841c-0da7-40dc-91ac-853744a68f86" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "4934d1f9-ea9d-4df3-88d4-97e1598edbb8", | |
| "latches": [ | |
| "d787da4e-1974-4926-8f70-1e533f9c42d5" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "49a96b55-774f-4c49-a319-cc1840b97c9d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "08cc915e-55f7-4ebd-ae6f-a409b244194d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "40b9fead-8f80-4584-bad8-d5de4b720fb5", | |
| "latches": [ | |
| "5e750bcd-7e95-4c61-b72f-75e56e27e043" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "361e2ac9-4f89-4e23-b653-e2a9ccdd10a5", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "0eb53495-f311-49ce-8191-135b63eae21f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "4a06d705-ea97-4a3a-be01-0e6541f75c12", | |
| "latches": [ | |
| "ae00dfce-0fd2-4e67-98a8-ce800880db8a" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "3e3a4073-dd88-4fe2-8957-3ec047b73a95", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "1a4ee6d0-ae5e-4b6c-9916-b7dd0a2ff168", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "2f09eca2-8d78-45cb-bbb0-c688f9d6d452", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "c8e9032c-4eda-4c70-b594-7afb147ea830", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "75e5841c-0da7-40dc-91ac-853744a68f86", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "asset", | |
| "instance": "dc4bfffd-3898-46de-b155-1fb1f9d73273", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Foxit Reader" | |
| ], | |
| [ | |
| "description", | |
| "The Foxit reader is the system that introduced the vulnerability.\n\ntype: vulnerable system" | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "3e6aa38e-ddfb-4661-8574-a6ee6ea88f57", | |
| "30": "a63dc42b-f47a-4cbe-9319-ae61333efb0a", | |
| "60": "44f9b5bc-219e-47b2-946d-692a85388907", | |
| "90": "eff4a499-1691-4053-bab5-9f8087eaf97d", | |
| "120": "f75729cd-a296-4c58-98a7-5ddb24d27d74", | |
| "150": "8905f649-1e8a-440f-bd3f-d63a4c38a459", | |
| "180": "c77dfba6-d32e-4997-aebe-3bbdaa33dd5d", | |
| "210": "d501d731-9bb6-492b-8c06-f6ac2f1d4717", | |
| "240": "3110a543-51a6-44fe-b1b0-4220cb19e6f6", | |
| "270": "c9e4e25c-d43d-47d3-a9ef-c035d72504b7", | |
| "300": "f7d88251-6733-401b-b531-9b65cf9dc471", | |
| "330": "3b058ab8-f553-4072-9c50-973702b8292f" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "3e6aa38e-ddfb-4661-8574-a6ee6ea88f57", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "a63dc42b-f47a-4cbe-9319-ae61333efb0a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "44f9b5bc-219e-47b2-946d-692a85388907", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "eff4a499-1691-4053-bab5-9f8087eaf97d", | |
| "latches": [ | |
| "33516144-de86-459b-8376-2e980c40ad5c" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "f75729cd-a296-4c58-98a7-5ddb24d27d74", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "8905f649-1e8a-440f-bd3f-d63a4c38a459", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "c77dfba6-d32e-4997-aebe-3bbdaa33dd5d", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "d501d731-9bb6-492b-8c06-f6ac2f1d4717", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "3110a543-51a6-44fe-b1b0-4220cb19e6f6", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "c9e4e25c-d43d-47d3-a9ef-c035d72504b7", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "f7d88251-6733-401b-b531-9b65cf9dc471", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "3b058ab8-f553-4072-9c50-973702b8292f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "asset", | |
| "instance": "901ff3f2-dc79-4889-b681-4761b76e7417", | |
| "properties": [ | |
| [ | |
| "name", | |
| "Host Operating System" | |
| ], | |
| [ | |
| "description", | |
| "The underlying operating system suffers the impact from the code execution, however, because the Foxit reader does not have its own security authority, the underlying operating system is considered the ultimate vulnerable system.\n\ntype: vulnerable system" | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "4d4cba92-ea70-4929-b52e-98385e79ced7", | |
| "30": "f904102f-b0ed-4eda-be8e-ff7e811fcc9c", | |
| "60": "4ed38d11-657b-489d-a6bc-7a7ace80b530", | |
| "90": "a4267b34-5bb3-4d33-b272-9ed84c221381", | |
| "120": "9b02f7cd-8734-4747-8051-70e51dd663cc", | |
| "150": "dd50a1f2-d3b9-4355-bfc9-ab02415db476", | |
| "180": "1a7e523d-fea8-42ad-af05-ac93b1e0703f", | |
| "210": "1d4f1556-61be-48eb-b1d7-52b20f93d2ef", | |
| "240": "7c9a2cca-a70c-434d-9aa1-a5dd2e815e59", | |
| "270": "028e6206-9d62-4edf-a3f5-842153c9ae1b", | |
| "300": "f6eb945a-e980-4753-8bd9-21ca2f9e556a", | |
| "330": "78e1210b-67a4-47ae-bc13-da9ee55226a6" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "4d4cba92-ea70-4929-b52e-98385e79ced7", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "f904102f-b0ed-4eda-be8e-ff7e811fcc9c", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "4ed38d11-657b-489d-a6bc-7a7ace80b530", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "a4267b34-5bb3-4d33-b272-9ed84c221381", | |
| "latches": [ | |
| "5dda4c76-88c3-4ff6-864e-3771164e2f3f" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "9b02f7cd-8734-4747-8051-70e51dd663cc", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "dd50a1f2-d3b9-4355-bfc9-ab02415db476", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "1a7e523d-fea8-42ad-af05-ac93b1e0703f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "1d4f1556-61be-48eb-b1d7-52b20f93d2ef", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "7c9a2cca-a70c-434d-9aa1-a5dd2e815e59", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "028e6206-9d62-4edf-a3f5-842153c9ae1b", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "f6eb945a-e980-4753-8bd9-21ca2f9e556a", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "78e1210b-67a4-47ae-bc13-da9ee55226a6", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "note", | |
| "instance": "4c979aea-f5c9-498d-b216-236b6ecdc92a", | |
| "properties": [ | |
| [ | |
| "abstract", | |
| "Impact Assessment" | |
| ], | |
| [ | |
| "content", | |
| "Because the injected code executes with the victim user’s privileges, it can interact with the underlying operating system, resulting in complete loss of confidentiality, integrity and availability for the OS environment accessible to that user.\n\nvector: C:H/I:H/A:H" | |
| ], | |
| [ | |
| "authors", | |
| [] | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "207a964b-b08d-46e5-8b59-8984ba086be9", | |
| "30": "db3be1d0-195e-44f1-8289-9a584107296f", | |
| "60": "37b1865d-c28b-4547-9e57-6524c6e08694", | |
| "90": "c975d4c0-0890-4544-80b9-266695782f18", | |
| "120": "47cc5e30-1715-4773-87c0-e3f8138f2a61", | |
| "150": "2078d02c-84d8-4558-8efd-425d193f1001", | |
| "180": "1c7cd529-d5ea-42c3-88d8-f6c33007c628", | |
| "210": "4995af78-8ed3-4900-8c54-a569db522973", | |
| "240": "ec87d77e-d54c-4a00-bd9a-720dbee87d64", | |
| "270": "dfa770c4-2346-4b45-9fdf-13806840e0a4", | |
| "300": "35639f2b-312b-4359-a0b8-1d0fd00bf765", | |
| "330": "3afa0670-2143-454c-8c38-bd18c9ad5b4c" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "207a964b-b08d-46e5-8b59-8984ba086be9", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "db3be1d0-195e-44f1-8289-9a584107296f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "37b1865d-c28b-4547-9e57-6524c6e08694", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "c975d4c0-0890-4544-80b9-266695782f18", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "47cc5e30-1715-4773-87c0-e3f8138f2a61", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "2078d02c-84d8-4558-8efd-425d193f1001", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "1c7cd529-d5ea-42c3-88d8-f6c33007c628", | |
| "latches": [ | |
| "a1805e26-a812-4e5b-8e64-9cff65a99149" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "4995af78-8ed3-4900-8c54-a569db522973", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "ec87d77e-d54c-4a00-bd9a-720dbee87d64", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "dfa770c4-2346-4b45-9fdf-13806840e0a4", | |
| "latches": [ | |
| "6d9a70f3-fa09-442e-8074-fd9005434bd1" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "35639f2b-312b-4359-a0b8-1d0fd00bf765", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "3afa0670-2143-454c-8c38-bd18c9ad5b4c", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "note", | |
| "instance": "ece290ee-cbb2-4796-9298-9d3ae05c0b69", | |
| "properties": [ | |
| [ | |
| "abstract", | |
| "Impact Assessment" | |
| ], | |
| [ | |
| "content", | |
| "The type-confusion allows arbitrary code to run in the Foxit Reader process, giving the attacker full read/write control over all data handled by the application and the ability to crash or disable it.\n\nvector: C:H/I:H/A:H" | |
| ], | |
| [ | |
| "authors", | |
| [] | |
| ] | |
| ], | |
| "anchors": { | |
| "0": "9cbc0847-1214-464e-8fa6-4f7e785dac39", | |
| "30": "0c0ddc0e-0c52-4bb1-a3d6-735cc94d801e", | |
| "60": "0ff51dac-1018-4402-b103-d9c4ad16be2b", | |
| "90": "504ea9e0-ce9f-4055-a988-ee197ac0f621", | |
| "120": "1f680e78-129b-4629-b5f1-926e7c860815", | |
| "150": "8cfd8531-be3c-49c8-9e85-adfd07037c88", | |
| "180": "b5aaa47c-ae4b-4e30-9c21-e8bbebfb1666", | |
| "210": "30975754-e68d-4bd8-ad61-322d05fbc236", | |
| "240": "37009470-83cc-4425-ba34-c5eb85d7791f", | |
| "270": "515b7a51-a2a4-40e6-8626-e45ac6dab7c0", | |
| "300": "fdf81a01-5920-4a04-9870-2cb3cbf9f797", | |
| "330": "27bd1aa3-5a9f-4c45-8790-cdb3f518782c" | |
| } | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "9cbc0847-1214-464e-8fa6-4f7e785dac39", | |
| "latches": [ | |
| "34b29a1f-50c6-4081-b505-4d8589543cc6" | |
| ] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "0c0ddc0e-0c52-4bb1-a3d6-735cc94d801e", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "0ff51dac-1018-4402-b103-d9c4ad16be2b", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "504ea9e0-ce9f-4055-a988-ee197ac0f621", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "1f680e78-129b-4629-b5f1-926e7c860815", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "8cfd8531-be3c-49c8-9e85-adfd07037c88", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "b5aaa47c-ae4b-4e30-9c21-e8bbebfb1666", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "30975754-e68d-4bd8-ad61-322d05fbc236", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "37009470-83cc-4425-ba34-c5eb85d7791f", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "515b7a51-a2a4-40e6-8626-e45ac6dab7c0", | |
| "latches": [ | |
| "75065683-d733-47d2-a956-36b30879d6c0" | |
| ] | |
| }, | |
| { | |
| "id": "vertical_anchor", | |
| "instance": "fdf81a01-5920-4a04-9870-2cb3cbf9f797", | |
| "latches": [] | |
| }, | |
| { | |
| "id": "horizontal_anchor", | |
| "instance": "27bd1aa3-5a9f-4c45-8790-cdb3f518782c", | |
| "latches": [] | |
| } | |
| ], | |
| "layout": { | |
| "42db24c5-e538-40c2-afe6-526b60bff84f": [ | |
| 50, | |
| -405 | |
| ], | |
| "886325eb-81c4-435a-a1cc-4b4d93490346": [ | |
| -190, | |
| 130 | |
| ], | |
| "e378a546-11e0-41f2-b342-5fc0c797b62d": [ | |
| -190, | |
| 500 | |
| ], | |
| "f21cce3d-ed65-43f4-887f-16ef7eda36ce": [ | |
| 45, | |
| 930 | |
| ], | |
| "ecee2a62-cc85-4aa3-8458-40204386d8d7": [ | |
| 270, | |
| 140 | |
| ], | |
| "3624bf53-a351-4e3c-82d1-ebe73f5f26e8": [ | |
| 270, | |
| 500 | |
| ], | |
| "a80e3520-96ae-45b9-bb3f-09148df0def5": [ | |
| 340, | |
| -145 | |
| ], | |
| "ccdb9aa7-2c06-4e4a-b482-b1843bb26b2a": [ | |
| 45, | |
| 1285 | |
| ], | |
| "dc4bfffd-3898-46de-b155-1fb1f9d73273": [ | |
| -180, | |
| 1725 | |
| ], | |
| "901ff3f2-dc79-4889-b681-4761b76e7417": [ | |
| 295, | |
| 1750 | |
| ], | |
| "4c979aea-f5c9-498d-b216-236b6ecdc92a": [ | |
| 529, | |
| 1349 | |
| ], | |
| "ece290ee-cbb2-4796-9298-9d3ae05c0b69": [ | |
| -451, | |
| 1349 | |
| ] | |
| }, | |
| "camera": { | |
| "x": 131, | |
| "y": 422, | |
| "k": 0.5000000000000008 | |
| } | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment