CVE-2021-41782: Use After Free
Published Aug 29, 2022
·Updated
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Affected Software
4 affected components
Foxit PDF Editor>=11.0<11.1
Foxit PDF Reader>=11.0<11.1
Foxit PhantomPDF<10.1.6
Microsoft Windows
Event History
Aug 29, 2022
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Foxit PDF Reader, PDF Editor, and PhantomPDF vulnerability?
The vulnerability ID for this Foxit PDF Reader, PDF Editor, and PhantomPDF vulnerability is CVE-2021-41782.
2
What is the severity of CVE-2021-41782?
The severity of CVE-2021-41782 is high (7.8).
3
Which software versions are affected by CVE-2021-41782?
Foxit PDF Reader versions 11.0 to 11.1, Foxit PDF Editor versions 11.0 to 11.1, and Foxit PhantomPDF versions up to 10.1.6 are affected by CVE-2021-41782.
4
How can an attacker exploit CVE-2021-41782?
An attacker can exploit CVE-2021-41782 by triggering a use-after-free vulnerability and executing arbitrary code through mishandled JavaScript in Foxit PDF Reader, PDF Editor, and PhantomPDF.
5
Is Microsoft Windows vulnerable to CVE-2021-41782?
No, Microsoft Windows is not vulnerable to CVE-2021-41782.