Use-after-free in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - #VU57228
Published: October 12, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a use-after-free error during URL path conversion in browser add-on, when processing a not accessible URL. A remote attacker can trick the victim to open a specially crafted PDF file in browser, trigger a use-after-free error and gain access to the NTLM v2 authentication credentials.
Affected software
Foxit PDF Reader for Windows
Remediation
Foxit PDF Reader for Windows - update to 11.1.0.52543