Impact
A use‑after‑free flaw is triggered when JavaScript embedded in a PDF deletes the current page; scripts that run afterward continue to access properties of the now‑invalid document view, causing Foxit PDF Editor and Foxit PDF Reader to crash. The vulnerability is recognised as CWE‑416 and results in a denial‑of‑service impact rather than arbitrary code execution.
Affected Systems
Foxit Software Inc. distributes the vulnerable code in both Foxit PDF Editor and Foxit PDF Reader. All released versions prior to the vendor’s latest update are potentially impacted; the advisory does not provide specific version ranges.
Risk and Exploitability
The attack vector is inferred to be the delivery of a crafted PDF file containing malicious JavaScript; any user who opens the file is at risk. The CVSS score of 7.8 indicates high severity for a remote denial‑of‑service vulnerability delivered via such a file. The EPSS score is below 1 %, implying a very low but non‑zero exploitation likelihood at the time of analysis. The vulnerability is not listed in the CISA KEV catalog and no widespread exploitation has been confirmed.
OpenCVE Enrichment