Input validation error in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2020-11493
Published: August 5, 2020 / Updated: September 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input when processing PDF files. A remote attacker can create a PDF file with specially crafted XObject, trick the victim into opening it and gain access to sensitive information or crash the application.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2020-11493
Foxit PDF Reader for Windows - update to 10.0.1