9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
9.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10 High
AI Score
Confidence
High
0.022 Low
EPSS
Percentile
89.4%
Multiple vulnerabilities were found in Foxit PDF Reader. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, obtain sensitive information, gain privileges.
Below is a complete list of vulnerabilities:
Security updates available in Foxit PDF Reader 11.2.1 and Foxit PDF Editor 11.2.1
CVE-2021-44708 critical
CVE-2021-44709 critical
CVE-2021-44741 high
CVE-2021-44740 high
CVE-2018-1285 critical
CVE-2021-40420 critical
CVE-2022-22150 critical
CVE-2022-24907 critical
CVE-2022-24363 critical
CVE-2022-24366 critical
CVE-2022-24908 critical
CVE-2022-24357 critical
CVE-2022-24358 critical
CVE-2022-24360 critical
CVE-2022-24359 critical
CVE-2022-24365 critical
CVE-2022-24362 critical
CVE-2022-24367 critical
CVE-2022-24369 critical
CVE-2022-24361 critical
CVE-2022-24364 critical
CVE-2022-24955 critical
CVE-2022-24954 critical
CVE-2022-24368 high
CVE-2022-24971 critical
CVE-2022-25108 high
Update to the latest version
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.
Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.
Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.
Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.
Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.
9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
9.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10 High
AI Score
Confidence
High
0.022 Low
EPSS
Percentile
89.4%