AI analysis
This vulnerability involves a use-after-free flaw in Foxit PDF Editor/Reader that allows embedded JavaScript to access form-field references after the fields are released, potentially causing application crashes. An attacker can exploit this by exploiting the unvalidated form-field references, gaining unauthorized access to sensitive system data or other application functionality. The affected scope includes Foxit PDF Editor/Reader across all known versions, though specific version ranges are not provided in the data. Current exploitation status is none_known, with no public PoC available.
What to do: Upgrade to patched versions of Foxit PDF Editor/Reader. Apply mitigations such as form-field lifecycle validation and input sanitization. Monitor affected products for deployment and verify compliance.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.