Impact
The flaw lies in the U3D Adobe Mesh Decompression routine used by Foxit PDF Editor and Reader. When the software parses a PDF that contains an abnormal Unity 3D object, it mistakenly treats part of the object data as a pointer and dereferences it as an address. This invalid memory access triggers a crash, preventing further use of the application. The weakness is a CWE‑787 and results in a denial‑of‑service scenario for the end user.
Affected Systems
Foxit Software Inc.’s PDF Editor and PDF Reader products are affected. The CVE record does not list specific vulnerable version ranges, so any installation of either product before the latest vendor update that patches the U3D de‑compression path could be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk level, while the EPSS score is recorded as less than 1% (0.0017), suggesting that exploitation events are currently rare. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector involves a malicious PDF file containing a malformed Unity 3D object; when a user opens the file, the application crashes. The exploit does not provide code execution or privilege escalation, but it does allow an attacker to cause service disruption and disrupt user productivity.
OpenCVE Enrichment