search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Foxit Reader vulnerable to arbitrary command execution

Vulnerability Note VU#570177

Original Release Date: 2010-04-02 | Last Revised: 2010-04-15

Overview

Foxit Reader contains a vulnerability that may allow an attacker to execute arbitrary commands without requiring user interaction.

Description

Foxit Reader is software designed to view Portable Document Format (PDF) files. The Adobe PDF Reference supports a "Launch action" that "... launches an application or opens or prints a document." Foxit Reader uses the ShellExecute function to handle PDFs that use a Launch action. In some cases, Foxit Reader will not prompt the user before an application is launched with a Launch action. It is also reported that the Launch Action can be used to launch an executable that is included in the PDF document, which results in arbitrary code execution.

Impact

By convincing a user to open a PDF document, e.g. by visiting a website, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.

Solution

Apply an update

This issue is addressed in Foxit Reader 3.2.1.0401. This update will cause Foxit Reader to prompt the user before using a Launch Action.

Vendor Information

570177
 

Foxit Software Company Affected

Notified:  March 30, 2010 Updated: April 02, 2010

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

This issue is addressed in Foxit Reader 3.2.1.0401. This update will cause Foxit Reader to prompt the user before using a Launch Action.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Didier Stevens.

This document was written by Will Dormann.

Other Information

CVE IDs: None
Severity Metric: 33.17
Date Public: 2010-03-31
Date First Published: 2010-04-02
Date Last Updated: 2010-04-15 14:31 UTC
Document Revision: 8

Sponsored by CISA.