Impact
The flaw is a use‑after‑free bug that occurs when a PDF file containing JavaScript resets form fields. The application does not validate the freed native object, and the subsequent function call crashes the program, resulting in a denial‑of-service condition on the device that opens the file. The weakness is identified as CWE‑416.
Affected Systems
Foxit Software Inc. publishes Foxit PDF Editor and Foxit PDF Reader. No specific version numbers are provided; any installation of these applications may be vulnerable unless a newer release with the fix is installed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a very low exploitation likelihood as of the latest data. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is embedding malicious JavaScript that resets form fields within a PDF file; a victim who opens such a file causes the application to crash, providing an insecure environment for attackers that rely on denial of service.
OpenCVE Enrichment