Impact
The vulnerability is a use‑after‑free flaw in Foxit’s PDF Editor and Reader that triggers during the processing of a PDF file. When a PDF is opened, the application resets annotation status and then fires a reset form event; during the subsequent re‑entry it accesses objects that have already been freed, causing a crash. This memory safety error results in an abrupt termination of the application and is classified as CWE‑416.
Affected Systems
Foxit PDF Editor and Foxit PDF Reader are affected. No specific version numbers are supplied by the CNA; administrators should verify that their deployments are running the most recent releases.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, reflecting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; a malicious PDF document that an end‑user opens could trigger the flaw. Given the lack of additional constraints, the vulnerability is potentially exploitable by an attacker who can deliver a crafted PDF to a victim’s machine.
OpenCVE Enrichment