QID 379064

Date Published: 2023-12-05

QID 379064: Foxit PDF Reader and Foxit PDF Editor 2023.3 Multiple Security Vulnerabilities

Foxit PDF Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PDF Editor is a business ready PDF toolkit, used to create professional PDF documents.

Addressed a potential issue where the application could be exposed to Remote Code Execution vulnerability when handling certain JavaScripts.

Affected versions:
Foxit PDF Reader versions 2023.2.0.21408 and earlier
Foxit PDF Editor version 2023.2.0.21408
Foxit PDF Editor version 2023.1.0.15510
Foxit PDF Editor version 13.0.0.21632
Foxit PDF Editor version 12.1.3.15356 and all previous 12.x versions
Foxit PDF Editor versions 11.2.7.53812 and all previous 11.x versions
Foxit PDF Editor versions 10.1.12.37872 and earlier

QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PDF Editor installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.

Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary code execution on the target system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    The vendor has issued a fix. For more information please visit Security updates available in Foxit PDF Reader 2023.3 and Foxit PDF Editor 2023.3
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Foxit PDF Reader 2023.3 and Foxit PDF Editor 2023.3 URL Logo www.foxit.com/support/security-bulletins.html