Improper Verification of Cryptographic Signature in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2022-25641
Published: May 9, 2022 / Updated: June 21, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to a parsing error when handling signatures in PDF files. A remote attacker can perform Incremental Saving Attack and Shadow Attack and deliver incorrect signature information when handling certain signed PDF files.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2022-25641
Foxit PDF Reader for Windows - update to 11.2.2.53575