PT-2023-2888 · Foxit · Foxit Pdf Reader

Andrea Micalizzi

+1

·

Published

2023-01-20

·

Updated

2024-05-03

·

CVE-2023-27363

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader versions 12.02 through 12.1.0
Description This issue allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability, where the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportXFAData method, which exposes a JavaScript interface that allows writing arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the current user. There have been reports of this issue being exploited in the wild, with a malicious PDF file being used as a dropper to persist via the startup folder and execute an infostealer.
Recommendations For Foxit PDF Reader versions 12.02 through 12.1.0, consider disabling the exportXFAData method as a temporary workaround until a patch is available. Restrict access to the JavaScript interface to minimize the risk of exploitation. Avoid using the exportXFAData method in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BDU:2023-02843
CVE-2023-27363
ZDI-23-491

Affected Products

Foxit Pdf Reader