ZDI-23-492: Foxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability
Published May 1, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Foxit PDF Editor
Event History
May 1, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 25, 2025
Advisory Published
via ZDI·06:59 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-492?
The ZDI-23-492 vulnerability is considered critical due to its potential for remote code execution.
2
How do I fix ZDI-23-492?
To fix ZDI-23-492, update Foxit PDF Editor to the latest version provided by the vendor.
3
What type of attack is associated with ZDI-23-492?
ZDI-23-492 can be exploited by remote attackers through malicious files or pages, requiring user interaction.
4
Which software is affected by ZDI-23-492?
ZDI-23-492 affects Foxit PDF Editor installations, specifically Foxit PhantomPDF for Windows.
5
What are the possible consequences of ZDI-23-492 exploitation?
Exploitation of ZDI-23-492 can lead to arbitrary code execution, compromising the affected system.