Impact
Foxit PDF Editor and Reader crash when a PDF containing embedded JavaScript modifies a form. The JavaScript alters form elements, but the application fails to manage the lifecycle of the affected PDF objects or validate null references. This path leads to a use‑after‑free error that terminates the process, CWE‑416, reflecting unsafe memory reference after deallocation.
Affected Systems
The vulnerability affects Foxit Software Inc.'s PDF Editor and PDF Reader applications. No specific versions are disclosed, so any installation of these products remains potentially affected until a vendor patch that addresses the use‑after‑free bug is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score is reported as < 1%, indicating a very low chance of exploitation at this time. The vulnerability does not appear in the CISA KEV catalog. Based on the description, the likely attack vector involves delivering a malicious PDF that contains JavaScript to modify a form; the victim must open the PDF in Foxit Editor or Reader. A remote or local attacker who can send the PDF to a user or embed it in a document management system can processes.
OpenCVE Enrichment