QID 376820
Date Published: 2022-08-16
QID 376820: Foxit Reader and Foxit PhantomPDF Prior to 8.2 Multiple Security Vulnerabilities
Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PhantomPDF Suite is a business ready PDF toolkit, used to create professional PDF documents.
Affected versions:
Foxit Reader version 8.1.4.1208 and earlier
Foxit PhantomPDF version 8.1.1.1115 and earlier
QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PhantomPDF installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.
Successful exploitation of these vulnerabilities may allow an attacker to either execute arbitrary code or information disclosure of the target system.
Solution
The vendor has issued a fix. For more information please visit Security updates available in Foxit Reader 8.2 and Foxit PhantomPDF 8.2
Vendor References
- Foxit Reader 8.2 and Foxit PhantomPDF 8.2 -
www.foxitsoftware.com/support/security-bulletins.html
CVEs related to QID 376820
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Foxit Reader 8.2 and Foxit PhantomPDF 8.2 |
|