ZDI-26-721: Foxit PDF Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader U3D integer overflow that can enable remote code execution.
ZDI-26-721 covers an integer overflow in Foxit PDF Reader while parsing U3D content, which can allow remote code execution. A user must open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91789. The advisory does not say the flaw is being exploited.
- U3D file parsing has an integer overflow.
- The flaw can lead to remote code execution.
- Exploitation needs a malicious file or page.
- ZDI rates it CVSS 7.8 as CVE-2026-91789.
Vulnerabilities mentionedAll →
- CVE-2026-917897.8—RCE in Foxit PDF Editor/Reader Texture Decoding Path (CVE-2026-91789)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91789 | RCE in Foxit PDF Editor/Reader Texture Decoding Path (CVE-2026-91789) Foxit PDF Editor/Reader contains a vulnerability in its U3D/GIF texture decoding path that lacks sufficient validation of image dimensions and size information. This flaw can cause incorrect memory allocation and a subsequent out-of-bounds write during pixel processing, potentially leading to remote code execution. An attacker could potentially exploit this to gain remote access or execute arbitrary code. The affected product is Foxit PDF Editor/Reader, and the current exploitation status is none known. Do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement strict image dimension and size validation, disable U3D/GIF texture decoding paths, and enforce strict memory bounds to prevent out-of-bounds writes. Regularly audit deployed plugins and verify exposure of sensitive processing paths. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91789.
This source does not provide full text. Read it at zerodayinitiative.com.