ZDI-26-301: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-5940.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-301?
ZDI-26-301 has a CVSS severity rating of 7.8, indicating a high risk level.
How do I fix ZDI-26-301?
To fix ZDI-26-301, update your Foxit PDF Reader to the latest version provided by the vendor.
What type of attack is associated with ZDI-26-301?
ZDI-26-301 is associated with a use-after-free vulnerability that allows remote code execution.
Is user interaction required to exploit ZDI-26-301?
Yes, user interaction is required as the target must visit a malicious webpage or open a harmful file.
What software is affected by ZDI-26-301?
The vulnerability affects installations of Foxit PDF Reader.