Remote Code Execution Vulnerability in Foxit PDF Editor
CVE-2021-34957
7.8HIGH
Summary
A remote code execution vulnerability in Foxit PDF Editor allows attackers to execute arbitrary code on installations of the product by exploiting a use-after-free flaw in the handling of Annotation objects. This issue stems from the absence of validation checks on object existence before executing operations. To successfully trigger this vulnerability, an attacker necessitates user interaction, requiring the user to either access a specifically crafted webpage or open a maliciously designed file. The consequence of this vulnerability includes the potential execution of arbitrary code within the context of the current user process, leading to severe security implications.
Affected Version(s)
PDF Editor 11.0.0.49893
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved