Remote Code Execution Vulnerability in Foxit PDF Reader
CVE-2021-34948

7.8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
7 May 2024

What is CVE-2021-34948?

A security flaw exists within Foxit PDF Reader that is related to the handling of Square annotation objects. The vulnerability arises due to a failure to validate the existence of these objects before operations are performed on them. If successfully exploited, this flaw allows remote attackers to execute arbitrary code on systems running an affected version of the software. User interaction is required, as the targeted user must open a malicious file or visit a compromised webpage to trigger the exploit. The exploitation of this vulnerability can lead to serious security breaches, enabling attackers to operate within the context of the current process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PDF Reader 11.0.0.49893

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.