Skip to main content

Foxit Reader Embedded Executable Code Injection Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 7 Apr 2010 5240 Views

RISK: Medium Risk

A vulnerability has been identified in Foxit Reader, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused due to Foxit Reader automatically running executable programs embedded within a PDF document without asking for a user's permission, which could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted PDF document.


Impact

  • Remote Code Execution

System / Technologies affected

  • Foxit Reader versions prior to 3.2.1.0401

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Foxit Reader version 3.2.1.0401 :
http://www.foxitsoftware.com/downloads/index.php


Vulnerability Identifier


Source