QID 375411
Date Published: 2021-04-05
QID 375411: Foxit Reader and Foxit PhantomPDF Remote Code Execution Vulnerability
Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PhantomPDF Suite is a business ready PDF toolkit, used to create professional PDF documents.
CVE-2021-27270 Addressed a potential issue where the application could be exposed to Out-of-Bounds Read vulnerability and crash
Affected versions:
Foxit Reader 10.1.1.37576 and earlier
Foxit PhantomPDF 10.1.1.37576 and earlier and earlier
QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PhantomPDF installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.
Application could be exposed to Out-of-Bounds Read vulnerability and crash, which could be exploited by attackers to execute remote code.
- CVE-2021-27270 -
www.foxitsoftware.com/support/security-bulletins.html
CVEs related to QID 375411
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-27270 |
|