VulnerabilityModified
CVE-2020-14425
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.
HIGH 7.8EPSS 40.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 40.78% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- foxitsoftware/foxit reader
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/159784/Foxit-Reader-9.7.1-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/48982Exploit, Third Party Advisory, VDB Entry
- https://www.foxitsoftware.com/support/security-bulletins.phpVendor Advisory
- http://packetstormsecurity.com/files/159784/Foxit-Reader-9.7.1-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/48982Exploit, Third Party Advisory, VDB Entry
- https://www.foxitsoftware.com/support/security-bulletins.phpVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.