Impact
Foxit PDF Editor and Foxit PDF Reader are vulnerable to a use‑after‑free flaw in list‑box field handling that is triggered when a PDF containing JavaScript is opened. The flaw, classified as CWE‑416: Use After Free, causes the application to reference an invalid pointer during repeated list‑box operations after a form reset, resulting in an illegal pointer read and an application crash. The impact is limited to denial of service as the crash terminates the process, with no evidence that it allows arbitrary code execution. The vulnerability is not a local privilege escalation or a remote code execution scenario.
Affected Systems
Both Foxit PDF Editor and Foxit PDF Reader are affected. The CVE does not provide specific version numbers, so all releases of these products should be treated as potentially vulnerable until a patch that contains the fix is applied. Updates for both editor and reader are available on the Foxit security bulletin page.
Risk and Exploitability
The CVSS base score of 7.8 indicates a significant service impact. The EPSS score of < 1% implies a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires a victim to open a malicious PDF that contains JavaScript, so social engineering or phishing is typically necessary. When exploitation occurs, the process crashes, potentially disrupting the user or any services that depend on the PDF application. Real‑world risk remains low but non‑zero, particularly in environments where users frequently open PDFs from untrusted sources.
OpenCVE Enrichment