Improper Verification of Cryptographic Signature in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2022-25641

 

Improper Verification of Cryptographic Signature in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2022-25641

Published: May 9, 2022 / Updated: June 21, 2022


Vulnerability identifier: #VU62885
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25641
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to a parsing error when handling signatures in PDF files. A remote attacker can perform Incremental Saving Attack and Shadow Attack and deliver incorrect signature information when handling certain signed PDF files.


Affected software

Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows

How to mitigate CVE-2022-25641

Install updates from vendor's website.

Foxit PDF Editor (formerly Foxit PhantomPDF) - addressed in versions 10.1.8.37795, 11.2.2.53575
Foxit PDF Reader for Windows - update to 11.2.2.53575

External References

Related Security Bulletins