Impact
The vulnerability is a use‑after‑free defect (CWE‑416) that allows JavaScript in a PDF to rewrite the page structure, invalidating page objects while the thumbnails still reference them, resulting in a crash. While the advisory title states the defect can be exploited for remote code execution, the official description only documents a crash; therefore the potential for arbitrary code execution remains unconfirmed but is a documented concern.
Affected Systems
Foxit Software Inc.’s Foxit PDF Editor and Foxit PDF Reader are impacted. The advisory does not list specific vulnerable versions, so any installed instance of these products could be at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% shows a very low probability of widespread exploitation in the near term. This vulnerability is not listed in CISA’s KEV catalog. An attacker can embed malicious JavaScript in a crafted PDF and prompt a user to open it; when the PDF is processed, the use‑after‑free condition will be triggered, causing a crash.
OpenCVE Enrichment