#VU101823 Improper verification of cryptographic signature in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF)
Published: December 18, 2024 / Updated: December 18, 2024
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit Software Inc.
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the application improperly ignores the changes to the “/NeedsRendering”
key or “TextField” field when verifying the XFA documents. A remote attacker perform spoofing attack and make users believe that the document is properly signed.