Foxit · Foxit Pdf Reader · CVE-2022-34873
**Name of the Vulnerable Software and Affected Versions**
Foxit PDF Reader version 11.2.1.53537
**Description**
This issue allows remote attackers to disclose sensitive information on affected installations. User interaction is required to exploit this, where the target must visit a malicious page or open a malicious file. The flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. This can be leveraged in conjunction with other issues to execute arbitrary code in the context of the current process.
**Recommendations**
For Foxit PDF Reader version 11.2.1.53537, consider disabling the handling of Annotation objects in JavaScript until a patch is available. Restrict access to malicious pages or files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.