Impact
Foxit Software’s PDF Editor and Reader contain a use‑after‑free flaw that occurs when JavaScript code resets form. This is a CWE‑416 use‑after‑free flaw. The synchronization logic does not guard against re‑entry or verify the object’s lifecycle, so the control pointer becomes invalid. The subsequent dereference causes the application to crash, denying service to legitimate users. This issue does not provide an attacker with remote code execution or data exfiltration capabilities, but it can be used to disrupt operations by causing the application to terminate unexpectedly.
Affected Systems
Foxit PDF Editor and Foxit PDF Reader on all platforms form control component is present listed for the vulnerability, so any installation that includes the form control is potentially affected.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, and the EPSS score of < 1% indicates a very low probability that a vulnerability will be exploited in the wild. The vulnerability is not listed in CISA's KEV in the wild. Based on the description, it is inferred that attackers can trigger the flaw by supplying a PDF file containing malicious JavaScript that resets a form. The likely attack vector is local exploitation via a crafted PDF opened by a user, or remote delivery through email or a web link. The lack of a known exploitation method and the KEV status reduce the immediate risk, but the DoS impact warrants prompt remediation.
OpenCVE Enrichment