AI analysis
A path traversal vulnerability in Foxit PDF Editor/Reader exists due to insufficient validation of embedded PDF resource file paths. This flaw allows files to be written outside their intended locations, potentially enabling arbitrary code execution. An attacker could gain full system control by exploiting the vulnerability. The affected products are Foxit PDF Editor/Reader, and the current exploitation status is unknown.
What to do: Upgrade to the latest version of Foxit PDF Editor/Reader to mitigate the path traversal vulnerability. Implement strict path validation and restrict resource file access to prevent arbitrary code execution. Regularly scan for known CVEs to detect and address security gaps.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.