First published: Wed Aug 11 2021(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1.4 | |
Foxitsoftware Phantompdf | <10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-38570.
The affected software is Foxit Reader and PhantomPDF before version 10.1.4.
This vulnerability has a severity rating of 9.1 (Critical).
Attackers can exploit this vulnerability to delete arbitrary files during uninstallation by using a symlink.
Yes, upgrading to version 10.1.4 or later of Foxit Reader and PhantomPDF can fix this vulnerability.