Impact
A use‑after‑free flaw occurs in Foxit PDF Editor and Reader when processing annotations in documents that include embedded JavaScript. The flaw allows the program to access memory after an annotation object has been released, which can trigger a crash or potentially enable remote code execution by executing arbitrary code placed in the corrupted memory area. The vulnerability is classified as CWE‑416.
Affected Systems
The flaw affects Foxit Software Inc.’s PDF Editor and PDF Reader applications. No specific vulnerable version numbers are reported, implying that the issue could exist in current releases used in the field.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the moment. The vulnerability is not listed in KEV. Attack vectors would involve a malicious PDF file sent to a user; the embedded JavaScript triggers the re‑entrant deletion, creating the use‑after‑free. Since the flaw can lead to arbitrary code execution, this presents a serious risk if attackers can embed malicious PDFs into legitimate workflows.
OpenCVE Enrichment