Remote Code Execution Vulnerability in Foxit PDF Reader
CVE-2021-34974

7.8HIGH

Key Information:

Vendor
Foxit
Vendor
CVE Published:
7 May 2024

Summary

A vulnerability exists in Foxit PDF Reader related to remote code execution that stems from improper handling of Annotation objects. The flaw allows an attacker to manipulate these objects without checking their existence, potentially leading to arbitrary code execution in the context of the user’s process. Exploitation requires the targeted user to open a specially crafted PDF file or visit a malicious web page containing harmful content. As this risk may lead to significant compromise, users are encouraged to keep their software updated and exercise caution while interacting with unknown files or links.

Affected Version(s)

PDF Reader 11.0.1.49938

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.