QID 375946
QID 375946: Foxit Reader and Foxit PhantomPDF Multiple Vulnerabilities
Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PhantomPDF Suite is a business ready PDF toolkit, used to create professional PDF documents.
CVE-2021-31469, CVE-2021-31471 : Application could be exposed to lack of proper validation of user-supplied data and attacker can execute arbitrary code
CVE-2021-31470, CVE-2021-31472, CVE-2021-31442, CVE-2021-31443, CVE-2021-31444, CVE-2021-31445, CVE-2021-31446, CVE-2021-31447, CVE-2021-31448, CVE-2021-31449 : Application has flaws handling of U3D objects in PDF files and An attacker can leverage this vulnerability to execute code
CVE-2021-31441, CVE-2021-31451 : Application has flaws handling of Annotation objects. An attacker can leverage this vulnerability to execute code
CVE-2021-31473 : Application has flaws within browseForDoc function. An attacker can leverage this vulnerability to execute code
CVE-2021-31450, CVE-2021-31452, CVE-2021-31453, CVE-2021-31455, CVE-2021-31459, CVE-2021-31460, CVE-2021-31462, CVE-2021-31463, CVE-2021-31464, CVE-2021-31465, CVE-2021-31466, CVE-2021-31467, CVE-2021-31468 : Application has flaws handling of XFA forms. An attacker can leverage this vulnerability to execute code
CVE-2021-31454 : Application has flaws handling of Decimal element. An attacker can leverage this vulnerability to execute code
CVE-2021-31456, CVE-2021-31457, CVE-2021-31458 : Application has flaws handling of Annotation objects. An attacker can leverage this vulnerability to execute code
CVE-2021-31461 : Application has flaws handling of app.media objects. An attacker can leverage this vulnerability to execute code
Affected versions:
Foxit Reader 10.1.3.37598 and earlier
Foxit PhantomPDF 10.1.3.37598 and earlier
QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PhantomPDF installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.
Successful exploitation could expose the application to Remote Code Execution vulnerability and crash.
CVEs related to QID 375946
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Foxit |
|