Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability
CVE-2021-34976

3.3LOW

Key Information:

Vendor
Foxit
Vendor
CVE Published:
7 May 2024

Summary

The vulnerability in Foxit PDF Reader arises from a flaw in the processing of PDF files, where the absence of validation for object existence before executing operations can lead to sensitive information being disclosed. An attacker can exploit this vulnerability by luring users into visiting a malicious webpage or opening a crafted PDF file. This exploitation may open pathways for further attacks by leveraging this weakness alongside other vulnerabilities, potentially allowing arbitrary code execution within the context of the running process.

Affected Version(s)

PDF Reader 11.0.1.49938

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.