ZDI-26-740: Foxit PDF Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader out-of-bounds write that can enable remote code execution.
ZDI published ZDI-26-740, an out-of-bounds write in Foxit PDF Reader PRC stream parsing tracked as CVE-2026-91811. Remote attackers could execute arbitrary code if a user opens a malicious file or visits a malicious page. ZDI assigned a CVSS score of 7.8. The advisory does not report exploitation in the wild.
- CVE-2026-91811 is an out-of-bounds write in PRC stream parsing.
- Exploitation can allow remote code execution on affected installations.
- A user must open a malicious file or visit a malicious page.
- ZDI rated the issue CVSS 7.8; no active exploitation is stated.
Vulnerabilities mentionedAll →
- CVE-2026-918117.8—Heap Out-of-Bounds Write in Foxit PDF Editor/Reader PRC 3D Parserpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91811 | Heap Out-of-Bounds Write in Foxit PDF Editor/Reader PRC 3D Parser CVE-2026-91811 is a heap-based out-of-bounds write (CWE-787) in the PRC parser of Foxit PDF Editor and Reader, caused by insufficient validation of vertex indices when parsing triangular fan texture meshes in PRC 3D content embedded in PDF files. An attacker triggers the flaw by convincing a user to open a specially crafted PDF containing malformed PRC 3D data; the CVSS 3.1 vector (7.8, AV:L/PR:N/UI:R) confirms user interaction is required and no privileges are needed. Successful exploitation corrupts heap memory, causing an application crash, and the High confidentiality/integrity/availability impact ratings indicate potential code execution in the context of the user running the application. Anyone using affected builds of Foxit PDF Editor or Foxit PDF Reader is exposed, with the risk concentrated in environments that routinely open PDFs from external senders. There is no known public proof-of-concept, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91811.
This source does not provide full text. Read it at zerodayinitiative.com.