CVE-2026-3779

7.8

Foxit · Foxit PDF Editor and Foxit PDF Reader

A use-after-free vulnerability in Foxit PDF Editor and Reader allows attackers to achieve arbitrary code execution via crafted documents.

Executive summary

A use-after-free vulnerability in Foxit PDF software allows for arbitrary code execution, posing a significant risk to system integrity.

Vulnerability

This vulnerability involves an improper memory management flaw within the list box calculate array logic. An attacker can trigger a use-after-free condition by providing a specially crafted document, which may lead to arbitrary code execution when the calculation function is executed.

Business impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with the privileges of the user running the application. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, data theft, or the installation of persistent malicious software.

Remediation

Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the latest versions provided by the vendor at their official security bulletin site.

Proactive Monitoring: Monitor endpoint logs for suspicious application crashes or unexpected child processes spawned by the PDF reader application.

Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious PDF attachments before they reach end users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the potential for arbitrary code execution, this vulnerability should be treated with high priority. Organizations using affected versions of Foxit PDF software must apply the latest vendor patches immediately to remediate the underlying memory safety issue and prevent potential exploitation.

More Foxit CVEs

Sources

Originally found and disclosed by KPC of Cisco Talos, per the CVE Program record.