#VU62885 Improper Verification of Cryptographic Signature in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF) - CVE-2022-25641
Published: May 9, 2022 / Updated: June 21, 2022
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit Software Inc.
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to a parsing error when handling signatures in PDF files. A remote attacker can perform Incremental Saving Attack and Shadow Attack and deliver incorrect signature information when handling certain signed PDF files.