Remote Information Disclosure Vulnerability in Foxit PDF Reader
CVE-2021-34973

3.3LOW

Key Information:

Vendor
Foxit
Vendor
CVE Published:
7 May 2024

Summary

A vulnerability exists in Foxit PDF Reader due to improper handling of the parsing process for PDF files. The flaw occurs from insufficient validation of an object's existence before performing operations on it. This oversight allows remote attackers to disclose sensitive information from compromised installations of the software. An exploit requires user interaction, as it necessitates that the victim visit a malicious webpage or open a harmful file. Attackers could pair this vulnerability with other existing security weaknesses to potentially execute arbitrary code in the context of the current process, further exacerbating the risk of unauthorized access or data breach.

Affected Version(s)

PDF Reader 11.0.1.49938

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.