CVE-2021-21822: Use After Free
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the browser plugin extension is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this use-after-free vulnerability?
The vulnerability ID for this use-after-free vulnerability is CVE-2021-21822.
What is the affected software?
The affected software is Foxit Software's PDF Reader version 10.1.3.37598.
What is the severity of CVE-2021-21822?
The severity of CVE-2021-21822 is high with a CVSS score of 8.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by tricking the user into opening a malicious PDF document.
Is there a fix available for this vulnerability?
Yes, Foxit Software has released a fix for this vulnerability. It is recommended to update to the latest version of Foxit Reader.