First published: Mon Aug 29 2022(Updated: )
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF Editor | >=11.0<11.1 | |
Foxit PDF Reader | >=11.0<11.1 | |
Foxit PhantomPDF | <10.1.6 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41784 is a vulnerability in Foxit PDF Reader, PDF Editor, and PhantomPDF that allows attackers to execute arbitrary code by triggering a use-after-free due to mishandling of JavaScript.
CVE-2021-41784 has a severity score of 7.8 (high).
Foxit PDF Reader before version 11.1, PDF Editor before version 11.1, and PhantomPDF before version 10.1.6 are affected by CVE-2021-41784.
An attacker can exploit CVE-2021-41784 by triggering a use-after-free vulnerability in Foxit PDF Reader, PDF Editor, or PhantomPDF through mishandling of JavaScript, allowing them to execute arbitrary code.
No, Microsoft Windows is not vulnerable to CVE-2021-41784.
You can find more information about CVE-2021-41784 in the security bulletins provided by Foxit: [link](https://www.foxit.com/support/security-bulletins.html).