QID 379064
Date Published: 2023-12-05
QID 379064: Foxit PDF Reader and Foxit PDF Editor 2023.3 Multiple Security Vulnerabilities
Foxit PDF Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Foxit PDF Editor is a business ready PDF toolkit, used to create professional PDF documents.
Addressed a potential issue where the application could be exposed to Remote Code Execution vulnerability when handling certain JavaScripts.
Affected versions:
Foxit PDF Reader versions 2023.2.0.21408 and earlier
Foxit PDF Editor version 2023.2.0.21408
Foxit PDF Editor version 2023.1.0.15510
Foxit PDF Editor version 13.0.0.21632
Foxit PDF Editor version 12.1.3.15356 and all previous 12.x versions
Foxit PDF Editor versions 11.2.7.53812 and all previous 11.x versions
Foxit PDF Editor versions 10.1.12.37872 and earlier
QID detection logic:(Authenticated)
This QID checks Windows Registry to get Foxit Reader and Foxit PDF Editor installation path and then reads corresponding executable((FoxitReader.exe/FoxitPhantomPDF.exe)) to see if it's running a vulnerable version.
Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary code execution on the target system.
- Foxit PDF Reader 2023.3 and Foxit PDF Editor 2023.3 -
www.foxit.com/support/security-bulletins.html
CVEs related to QID 379064
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Foxit PDF Reader 2023.3 and Foxit PDF Editor 2023.3 |
|