Remote Information Disclosure Vulnerability in Foxit PDF Reader
CVE-2021-34973
3.3LOW
Summary
A vulnerability exists in Foxit PDF Reader due to improper handling of the parsing process for PDF files. The flaw occurs from insufficient validation of an object's existence before performing operations on it. This oversight allows remote attackers to disclose sensitive information from compromised installations of the software. An exploit requires user interaction, as it necessitates that the victim visit a malicious webpage or open a harmful file. Attackers could pair this vulnerability with other existing security weaknesses to potentially execute arbitrary code in the context of the current process, further exacerbating the risk of unauthorized access or data breach.
Affected Version(s)
PDF Reader 11.0.1.49938
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved