CVE-2021-41783: Use After Free
Published Aug 29, 2022
·Updated
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Affected Software
4 affected components
Foxit PDF Editor>=11.0<11.1
Foxit PDF Reader>=11.0<11.1
Foxit PhantomPDF<10.1.6
Microsoft Windows
Event History
Aug 29, 2022
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41783.
2
What is the severity of CVE-2021-41783?
The severity of CVE-2021-41783 is rated as high (7.8).
3
Which software versions are affected by CVE-2021-41783?
Foxit PDF Reader versions before 11.1, PDF Editor versions before 11.1, and PhantomPDF versions before 10.1.6 are affected by CVE-2021-41783.
4
How can an attacker exploit CVE-2021-41783?
An attacker can exploit CVE-2021-41783 by triggering a use-after-free vulnerability and executing arbitrary code due to mishandling of JavaScript.
5
Where can I find more information about CVE-2021-41783?
More information about CVE-2021-41783 can be found on the Foxit website's security bulletins page.