Improper Verification of Cryptographic Signature in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2021-40326
Published: October 12, 2021
Vulnerability identifier: #VU57225
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40326
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient verification of digital signatures in PDF files. A remote attacker can display arbitrary content in the signed PDF file.
Affected software
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows
Foxit PDF Reader for Windows
How to mitigate CVE-2021-40326
Install updates from vendor's website.
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 11.1.0.52543
Foxit PDF Reader for Windows - update to 11.1.0.52543
Foxit PDF Reader for Windows - update to 11.1.0.52543