#VU57228 Use-after-free in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF)
Published: October 12, 2021
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit Software Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a use-after-free error during URL path conversion in browser add-on, when processing a not accessible URL. A remote attacker can trick the victim to open a specially crafted PDF file in browser, trigger a use-after-free error and gain access to the NTLM v2 authentication credentials.