The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtaine...
Description
The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtained before deletion, triggering an illegal read and crashing
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Foxit
PRODUCT: Foxit PDF Editor / Foxit PDF Reader
AFFECTED_VERSIONS: Foxit PDF Editor: 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier; Foxit PDF Reader: 2026.1.1 and earlier
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A use-after-free vulnerability in Foxit PDF Editor and Reader occurs when the software incorrectly processes document fields after a page deletion, leading to an illegal memory read.
Executive Summary:
An illegal memory read vulnerability in Foxit PDF Editor and Reader, resulting from improper field processing, may allow an attacker to crash the application or execute arbitrary code.
Vulnerability Details
CVE-ID: CVE-2026-57247
Affected Software: Foxit PDF Editor and Foxit PDF Reader
Affected Versions: Foxit PDF Editor: 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier; Foxit PDF Reader: 2026.1.1 and earlier
Vulnerability: This vulnerability (CWE-416) is triggered when the application re-enters document structures during field processing and attempts to access objects that were previously deleted. An unauthenticated attacker can exploit this by providing a malicious PDF document designed to trigger this specific lifecycle error.
Business Impact
This vulnerability presents a high risk to business operations, as it can lead to application crashes (denial of service) or potential remote code execution. With a CVSS score of 7.8, the impact on workstations—where these products are primarily deployed—is significant, necessitating prompt remediation to prevent compromise.
Remediation Plan
Immediate Action: Update to the most recent version of Foxit PDF Editor or Reader as specified in the official vendor security bulletin.
Proactive Monitoring: Monitor for application crashes or logs indicating illegal read operations within the PDF processing component.
Compensating Controls: Ensure that endpoint protection software is configured to detect and prevent memory-based attacks.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 8, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The complexity of the document structure processing makes this a sensitive area for security. Administrators must prioritize the deployment of vendor-supplied patches to eliminate this use-after-free risk and maintain the security posture of their environments.