CVE-2021-38571: High severity Foxitsoftware Foxit Reader vulnerability
Published Aug 11, 2021
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
Affected Software
8 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<9.7.5.29616
Foxitsoftware Phantompdf>=10.0.0.0<10.1.4
Microsoft Windows
All of the following
Any of the following
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<9.7.5.29616
Foxitsoftware Phantompdf>=10.0.0.0<10.1.4
Microsoft Windows
Event History
Aug 11, 2021
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38571?
CVE-2021-38571 is a DLL hijacking vulnerability in Foxit Reader and PhantomPDF.
2
What is the severity of CVE-2021-38571?
CVE-2021-38571 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2021-38571?
Foxit Reader versions up to but not including 10.1.4, PhantomPDF versions up to but not including 9.7.5.29616, and PhantomPDF versions up to but not including 10.1.4 are affected.
4
How can I fix CVE-2021-38571?
To fix CVE-2021-38571, update Foxit Reader to version 10.1.4 or higher, and update PhantomPDF to version 9.7.5.29616 or higher.
5
Where can I find more information about CVE-2021-38571?
More information about CVE-2021-38571 can be found at the following URL: https://www.foxitsoftware.com/support/security-bulletins.php