QID 375770
Date Published: 2021-08-05
QID 375770: Foxit Reader and Foxit PhantomPDF Multiple Vulnerabilities
Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PhantomPDF Suite is a business ready PDF toolkit, used to create professional PDF documents.
Affected versions:
Foxit PDF Reader 11.0.0.49893 and earlier
Foxit PDF Editor 11.0.0.49893 and earlier
QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PhantomPDF installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.
Successful exploitation could expose the application to Out-of-Bounds Write Remote Code Execution vulnerability and crash.
Solution
The vendor has issued a fix. For more information please visit advisory
Vendor References
CVEs related to QID 375770
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Foxit |
|