OS Command Injection in Foxit Software Inc. products - #VU89812
Published: May 24, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when opening certain PDFs that include the Launch File action. A remote attacker can trick the victim to open a specially crafted PDF file and lick on the "OK" button to execute arbitrary commands on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Foxit PDF Reader for Windows
Foxit PDF Reader for Mac
Foxit PDF Editor for Mac (formerly PhantomPDF)
Remediation
Foxit PDF Reader for Windows - update to 2024.2.2.25170
Foxit PDF Reader for Mac - update to 2024.2.2
Foxit PDF Editor for Mac (formerly PhantomPDF) - update to 2024.2.2.64388