Foxit, Epic Games Store, MedDreams vulnerabilities
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住主要信息。 文章提到Cisco Talos团队发现了多个漏洞,涉及Foxit PDF Editor、Epic Games Store和MedDream PACS。具体来说,Foxit有三个漏洞,包括权限提升和内存问题;Epic有一个权限提升漏洞;MedDream有21个XSS漏洞。这些漏洞都已经被修复了,并且提供了检测工具和建议。 接下来,我需要将这些信息浓缩到100字以内。要确保涵盖所有主要软件及其漏洞类型,并提到修复情况和安全建议。这样用户就能快速了解文章的核心内容了。 最后,检查字数是否符合要求,并确保语言简洁明了。 </think> Cisco Talos团队披露了Foxit PDF Editor的三个漏洞(包括权限提升和内存问题)、Epic Games Store的一个权限提升漏洞以及MedDream PACS的21个反射型跨站脚本(XSS)漏洞。所有漏洞均已修复,并提供检测工具和安全建议。 2026-1-22 14:2:5 Author: blog.talosintelligence.com(查看原文) 阅读量:0 收藏

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in Foxit PDF Editor, one in the Epic Games Store, and twenty-one in MedDream PACS..

The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.    

For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.     

Foxit privilege escalation and use-after-free vulnerabilities

Discovered by KPC of Cisco Talos.

Foxit PDF Editor is a popular PDF handling platform for editing, e-signing, and collaborating on PDF documents. Talos found three vulnerabilities:

TALOS-2025-2275 (CVE-2025-57779) is a privilege escalation vulnerability in the installation of Foxit PDF Editor via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in elevation of privileges.

TALOS-2025-2277 (CVE-2025-58085) and TALOS-2025-2278 (CVE-2025-59488)  are use-after-free vulnerabilities, one in the way Foxit Reader handles a Barcode field object, and one in the way Foxit Reader handles a Text Widget field object. A specially crafted JavaScript code inside a malicious PDF document can trigger these vulnerabilities, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger these vulnerabilities. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

Epic Games local privilege escalation vulnerability

Discovered by KPC of Cisco Talos.

Epic Games Store is a storefront application for purchasing and accessing video games. Talos found TALOS-2025-2279 (CVE-2025-61973), a local privilege escalation vulnerability in the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in elevation of privileges.

MedDream PACS reflected cross-site scripting vulnerabilities

Discovered by Marcin “Icewall” Noga of Cisco Talos.

MedDream PACS server is a medical-integration system for archiving and communicating about DICOM 3.0 compliant images. Talos found 21 reflected cross-site scripting (XSS) vulnerabilities across several functions of MedDream PACS Premium 7.3.6.870. An attacker can provide a specially crafted URL to trigger these vulnerabilities, which can lead to arbitrary JavaScript code execution. 


文章来源: https://blog.talosintelligence.com/foxi-and-epic-games/
如有侵权请联系:admin#unsafe.sh