Description
Foxit PDF Reader <  4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
Published: 2025-08-20
Score: 8.4 High
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2011-5258 Foxit PDF Reader <  4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
History

Thu, 20 Nov 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Foxit
Foxit pdf Editor
CPEs cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Vendors & Products Foxit
Foxit pdf Editor

Fri, 22 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Reader

Wed, 20 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
Description Foxit PDF Reader <  4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
Title Foxit PDF Reader < 4.3.1.0218 JavaScript File Write
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Foxit Pdf Editor
Foxitsoftware Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-07T14:02:18.585Z

Reserved: 2025-08-19T15:24:59.359Z

Link: CVE-2011-10030

cve-icon Vulnrichment

Updated: 2025-08-22T15:48:16.009Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T16:15:36.150

Modified: 2026-04-15T00:35:42.020

Link: CVE-2011-10030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-21T12:58:59Z

Weaknesses