CVE-2020-26538

Description

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.012

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Foxit Reader 10.0.1.35811Windows
Multiple vulnerabilities affected in Foxit PhantomPDF 10 (EXE) 10.0.1.35811Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-334489Foxit Reader (2023.3.0.23028)
PATCH-331212Foxit PhantomPDF 10 (EXE) (10.1.12.37872)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234