Remote Code Execution Flaw in Foxit PhantomPDF
CVE-2021-27270

7.8HIGH

Key Information:

Vendor
Foxit
Vendor
CVE Published:
30 March 2021

Summary

A remote code execution vulnerability exists in Foxit PhantomPDF versions prior to 10.1.0.37527, which allows attackers to execute arbitrary code on the system. This flaw is triggered when a user visits a malicious webpage or opens a compromised file that contains specially crafted JPEG2000 images. The underlying issue is a failure to properly validate user-supplied input, potentially enabling attackers to read past allocated memory structures, thereby executing code within the current context. For mitigation, users are advised to update to the latest version.

Affected Version(s)

PhantomPDF 10.1.0.37527

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cece
.