Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
CVE-2021-34969

5.5MEDIUM

Key Information:

Vendor

Foxit

Vendor
CVE Published:
7 May 2024

What is CVE-2021-34969?

The vulnerability arises from a flaw in the handling of Annotation objects within Foxit PDF Reader. This flaw occurs due to the absence of adequate validation of an object's existence before executing operations on it. Exploitation of this issue requires user interaction, as it involves navigating to a malicious webpage or opening a malicious PDF file. Once exploited, an attacker could potentially disclose sensitive information or leverage this vulnerability alongside others to execute arbitrary code within the current process context.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PDF Reader 11.0.1.49938

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.