PT-2021-5421 · Foxit · Foxit Pdf Reader+1

Cor3Sm4Sh3R

·

Published

2021-10-15

·

Updated

2024-05-08

·

CVE-2021-34955

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader and Foxit PDF Editor (affected versions not specified)
Description The issue is caused by a use-after-free error in the handling of Annotation objects, resulting from the lack of validation of an object's existence before performing operations on it. This allows remote attackers to execute arbitrary code on affected installations by exploiting the vulnerability through a malicious page or file. User interaction is required, where the target must visit a malicious page or open a malicious file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2021-06264
CVE-2021-34955
ZDI-21-1186

Affected Products

Foxit Pdf Editor
Foxit Pdf Reader