Impact
Foxit PDF Editor and Reader contain a use‑after‑free flaw triggered when the program processes hyperlinks in PDF annotations. The malformed annotation data fails to validate the relationships and field combinations, causing internal objects to enter an invalid state. When the application writes through an invalid pointer, it crashes. The immediate effect is a denial of service for the user, and the description does not indicate any capability for code execution based on the information provided.
Affected Systems
Affected products include Foxit PDF Editor and Foxit PDF Reader, as specified by Foxit Software Inc. No specific version numbers are listed, so the vulnerability should be addressed when a patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not recorded in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The attack vector is inferred to be local use: an attacker can provide a crafted PDF to a user, triggering the crash when the file is opened. While remote exploitation via network does not appear supported by the description, the risk of abuse remains if a malicious file is distributed or delivered through phishing. Given the severity score and the potential for denial of service, timely remediation is recommended.
OpenCVE Enrichment