SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14425

Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.

HIGH 7.8EPSS 40.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 40.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
40.78% probability · 99th percentile
CISA KEV
Not listed
Affected
foxitsoftware/foxit reader
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.