AI analysis
Foxit PDF Editor/Reader has a vulnerability where it fails to validate the directory traversal path in attached PDF filenames, allowing malicious files to be written to directories outside the expected secure area when the PDF is opened. This flaw is triggered by an attacker who can manipulate the filename to bypass path restrictions. An attacker can therefore gain unauthorized access to sensitive directories and potentially execute arbitrary commands or modify system files. The affected scope is limited to Foxit PDF Editor/Reader, and current public exploitation is not known.
What to do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement and enforce strict path validation and sandboxed attachment handling to prevent directory traversal. Regularly audit and scan for exposed PDF attachments and restrict access to secure directories.
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.