Impact
During the PRC parsing stage in Foxit PDF Editor and Reader, a missing boundary check on the PRC entity index allows an out‑of‑bounds read of the entity array, causing the application to crash. Because the flaw does not leak data or allow code execution, the primary impact is a denial of service that can interrupt business processes when a malicious PDF is opened.
Affected Systems
Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. Version details were not disclosed in the advisory, so all pre‑patch releases remain vulnerable.
Risk and Exploitability
The CVSS score of 6.1 classifies the vulnerability as medium severity, while the EPSS score (<1%) indicates a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting no known active exploitation. The most probable attack vector is an adversary supplying a crafted PDF containing a malicious PRC section crashes, resulting in service disruption rather than remote code execution.
OpenCVE Enrichment