QID 375411

Date Published: 2021-04-05

QID 375411: Foxit Reader and Foxit PhantomPDF Remote Code Execution Vulnerability

Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PhantomPDF Suite is a business ready PDF toolkit, used to create professional PDF documents.

CVE-2021-27270 Addressed a potential issue where the application could be exposed to Out-of-Bounds Read vulnerability and crash

Affected versions:
Foxit Reader 10.1.1.37576 and earlier
Foxit PhantomPDF 10.1.1.37576 and earlier and earlier

QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PhantomPDF installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.

Application could be exposed to Out-of-Bounds Read vulnerability and crash, which could be exploited by attackers to execute remote code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The vendor has issued a fix. For more information please visit advisory
    Vendor References

    CVEs related to QID 375411

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27270 URL Logo www.foxitsoftware.com/support/security-bulletins.html