CVE-2011-10030: Foxit PDF Reader < 4.3.1.0218 JavaScript File Write
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-10030?
CVE-2011-10030 has a high severity level due to its ability to allow arbitrary file writing on the system.
How do I fix CVE-2011-10030?
To fix CVE-2011-10030, update Foxit PDF Reader to version 4.3.1.0218 or later.
What impact does CVE-2011-10030 have on my system?
CVE-2011-10030 can allow an attacker to write files to any location on disk, potentially leading to system compromise.
Which versions of Foxit PDF Reader are affected by CVE-2011-10030?
CVE-2011-10030 affects Foxit PDF Reader versions before 4.3.1.0218.
Is CVE-2011-10030 a remote or local vulnerability?
CVE-2011-10030 is considered a local vulnerability, as it requires the execution of a malicious PDF file by the user.