Remote Code Execution Vulnerability in Foxit PDF Editor
CVE-2021-34957

7.8HIGH

Key Information:

Vendor
Foxit
Vendor
CVE Published:
7 May 2024

Summary

A remote code execution vulnerability in Foxit PDF Editor allows attackers to execute arbitrary code on installations of the product by exploiting a use-after-free flaw in the handling of Annotation objects. This issue stems from the absence of validation checks on object existence before executing operations. To successfully trigger this vulnerability, an attacker necessitates user interaction, requiring the user to either access a specifically crafted webpage or open a maliciously designed file. The consequence of this vulnerability includes the potential execution of arbitrary code within the context of the current user process, leading to severe security implications.

Affected Version(s)

PDF Editor 11.0.0.49893

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.