Remote Code Execution Vulnerability in Foxit PDF Reader
CVE-2021-34974
7.8HIGH
Summary
A vulnerability exists in Foxit PDF Reader related to remote code execution that stems from improper handling of Annotation objects. The flaw allows an attacker to manipulate these objects without checking their existence, potentially leading to arbitrary code execution in the context of the user’s process. Exploitation requires the targeted user to open a specially crafted PDF file or visit a malicious web page containing harmful content. As this risk may lead to significant compromise, users are encouraged to keep their software updated and exercise caution while interacting with unknown files or links.
Affected Version(s)
PDF Reader 11.0.1.49938
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved