CVE-2026-3779
7.8Foxit · Foxit PDF Editor and Foxit PDF Reader
A use-after-free vulnerability in Foxit PDF Editor and Reader allows attackers to achieve arbitrary code execution via crafted documents.
Executive summary
A use-after-free vulnerability in Foxit PDF software allows for arbitrary code execution, posing a significant risk to system integrity.
Vulnerability
This vulnerability involves an improper memory management flaw within the list box calculate array logic. An attacker can trigger a use-after-free condition by providing a specially crafted document, which may lead to arbitrary code execution when the calculation function is executed.
Business impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with the privileges of the user running the application. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, data theft, or the installation of persistent malicious software.
Remediation
Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the latest versions provided by the vendor at their official security bulletin site.
Proactive Monitoring: Monitor endpoint logs for suspicious application crashes or unexpected child processes spawned by the PDF reader application.
Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious PDF attachments before they reach end users.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the potential for arbitrary code execution, this vulnerability should be treated with high priority. Organizations using affected versions of Foxit PDF software must apply the latest vendor patches immediately to remediate the underlying memory safety issue and prevent potential exploitation.
More Foxit CVEs
Sources
Originally found and disclosed by KPC of Cisco Talos, per the CVE Program record.