Impact
The PRC file header parser in Foxit PDF Editor and Foxit PDF Reader incorrectly trusts the constructed file structure description, assumes the underlying array contains elements, and reads past the array bounds. When a PDF containing a maliciously crafted PRC 3D stream is opened, the application attempts an out‑of‑bounds read, causing the program to terminate, resulting in a denial of service for the current user session.
Affected Systems
Foxit Software Inc.'s Foxit PDF Editor and Foxit PDF Reader are affected. Version information has not been published, so all releases until the next vendor update should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.1 classifies the flaw as moderate risk, while an EPSS score of < 1% indicates a very low likelihood of exploitation. The observed effect is a crash, causing a denial of service on the user session. The issue is not listed in the CISA KEV catalog, further diminishing the current threat weight.
OpenCVE Enrichment