Remote Code Execution Flaw in Foxit PhantomPDF
CVE-2021-27270
7.8HIGH
Summary
A remote code execution vulnerability exists in Foxit PhantomPDF versions prior to 10.1.0.37527, which allows attackers to execute arbitrary code on the system. This flaw is triggered when a user visits a malicious webpage or opens a compromised file that contains specially crafted JPEG2000 images. The underlying issue is a failure to properly validate user-supplied input, potentially enabling attackers to read past allocated memory structures, thereby executing code within the current context. For mitigation, users are advised to update to the latest version.
Affected Version(s)
PhantomPDF 10.1.0.37527
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
cece