Impact
Foxit PDF Editor and PDF Reader contain a use‑after‑free weakness that is triggered when JavaScript modifies the properties of form fields in a PDF document. The program fails to invalidate or correctly re‑reference the underlying objects, leading to a read of an illegal memory address and an application crash. This outcome is a denial of service; the available information does not indicate that arbitrary code execution can be achieved.
Affected Systems
Foxit Software Inc. offers the vulnerable products. The Foxit PDF Editor and Foxit PDF Reader are affected. No specific version information is supplied, so users should verify whether their installations contain the fix or upgrade to the latest releases from Foxit.
Risk and Exploitability
The CVSS base score of 7.8 reflects a high‑severity flaw that impacts availability. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely embed a malicious PDF containing JavaScript that alters form fields and deliver it through phishing emails or compromised websites, aiming to cause the application to crash when a user opens the file. No evidence suggests that the flaw can be leveraged for remote code execution or privilege escalation.
OpenCVE Enrichment