Heap-based Buffer Overflow Remote Code Execution Vulnerability in Foxit PDF Reader
CVE-2021-34971

7.8HIGH

Key Information:

Vendor
Foxit
Vendor
CVE Published:
7 May 2024

Summary

A vulnerability exists within Foxit PDF Reader that allows remote attackers to execute arbitrary code by exploiting a parsing error in JPG2000 files. The flaw stems from inadequate validation of user-supplied data length prior to buffer allocation in heap memory. As a consequence, when a targeted user opens a maliciously crafted JPG2000 file or navigates to an unsafe web page, an attacker can gain unauthorized access and execute code within the context of the affected application. This vulnerability highlights the critical importance of robust input validation and secure coding practices. For detailed information, consult the vendor's advisory and relevant security bulletins.

Affected Version(s)

PDF Reader 11.0.1.49938

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.