CVE-2023-27363: Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the exportXFAData method. The application exposes a JavaScript interface that allows writing arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19697.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27363?
CVE-2023-27363 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-27363?
To mitigate CVE-2023-27363, users should update to the latest version of Foxit PDF Reader as soon as it is available.
What types of installations are affected by CVE-2023-27363?
CVE-2023-27363 affects all installations of Foxit PDF Reader that are not updated to include the security patch.
Does CVE-2023-27363 require user interaction to exploit?
Yes, CVE-2023-27363 requires user interaction, meaning an attacker must trick a user into opening a malicious document.
What impact does CVE-2023-27363 have on a system?
Successful exploitation of CVE-2023-27363 can lead to remote code execution, allowing attackers to run arbitrary code on the affected system.