Foxit PDF Reader < 4.3.1.0218 JavaScript File Write
Vulnerability Description
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10030
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chris Evans
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/foxit_reader_filewrite.rb
- https://www.exploit-db.com/exploits/16978
- http://scarybeastsecurity.blogspot.com/2011/03/dangerous-file-write-bug-in-foxit-pdf.html
- https://www.foxit.com/pdf-reader/version-history.html
- https://www.vulncheck.com/advisories/foxit-pdf-reader-javascript-file-write
More from Foxit Software
View All →Affected Vendor
Foxit Software
View all reports →