Impact
Foxit PDF Editor and Foxit PDF Reader contain a use‑after‑free flaw that appears during the processing of document fields. When the application re‑enters the document structure, it deletes the current page and subsequently continues to use the field objects that were allocated prior to that deletion, which leads to an illegal memory read and results in a crash. The flaw is classified as CWE‑416 and can allow an attacker to cause a denial of service on the affected workstation or device.
Affected Systems
The vulnerability affects all editions of Foxit PDF Editor and Foxit PDF Reader distributed by Foxit Software Inc. Because no specific version numbers are disclosed in the CNA data, all installed instances are potentially vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 7.8 signals a moderate‑to‑high risk if exploited. The EPSS score of < 1% indicates a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, implying no known active exploitation. A likely attack vector appears to be the delivery of a crafted PDF document to the victim; based on the nature of the use‑after‑free triggered by field processing, this inference is derived from the description but is not explicitly stated in the CVE data.
OpenCVE Enrichment