AI analysis
Foxit PDF Editor/Reader can execute reentrant zoom and layout operations through page- and annotation-related JavaScript actions when processing specially crafted PDFs. This vulnerability allows the application to access page objects that have been released, triggering a use-after-free condition and causing an application crash. An attacker can potentially gain unauthorized access and privileges, and could leverage the vulnerability to exfiltrate data or perform other malicious actions. The affected products are Foxit PDF Editor/Reader, and the current exploitation status is none known.
What to do: Upgrade to the latest version of Foxit PDF Editor/Reader; disable reentrant zoom and layout operations; monitor page/annotation JS actions; verify no page objects are released before use.
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.