Vulnerability record · CVE-2009-0837 · published 10 March 2009
CVE-2009-0837: Foxit Reader stack buffer overflow via long filename path in action
Foxit · Reader3.0
Foxit Reader 3.0 before Build 1506 (including 1120 and 1301) contains a stack-based buffer overflow when processing a long relative or absolute path in the filename argument of an action, such as the 'Open/Execute a file' action. A crafted PDF can trigger the overflow and corrupt the stack, which matters because the reader is a common document viewer and the flaw is remotely reachable.
Description
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with no authentication and has a very high EPSS score, though it is not in KEV and affects an old, likely replaced version.
What it is
Foxit Reader 3.0 before Build 1506 (including 1120 and 1301) contains a stack-based buffer overflow when processing a long relative or absolute path in the filename argument of an action, such as the 'Open/Execute a file' action. A crafted PDF can trigger the overflow and corrupt the stack, which matters because the reader is a common document viewer and the flaw is remotely reachable.
Impact
An attacker can execute arbitrary code in the context of the user running Foxit Reader. Because the CVSS vector rates confidentiality, integrity and availability as complete, a successful exploit can fully compromise the host process and potentially the user's session.
Attack surface
The flaw is reached remotely over the network when a user opens a malicious PDF containing a crafted action with an oversized filename path. No authentication is required, but user interaction (opening the document) is implied by the vector and the reader context.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75781, 99.5th percentile), indicating a strong likelihood of exploitation activity. References are vendor advisories and third-party write-ups rather than public exploit code tags.
What to do
- Upgrade Foxit Reader to Build 1506 or later, or to a currently supported release.
- If upgrade is not possible, disable or restrict the 'Open/Execute a file' action and other action handling in Foxit Reader policy settings.
- Block untrusted PDFs at email and web gateways, and enforce attachment filtering for PDFs from external sources.
- Run Foxit Reader with least privilege and enable OS-level exploit mitigations (DEP, ASLR) where available.
- Consider an alternative hardened PDF reader for high-risk users until the affected version is removed.
Detection
- Monitor for Foxit Reader process crashes or abnormal terminations, especially when opening PDFs from email or web downloads.
- Search endpoint logs for child processes spawned by Foxit Reader, which may indicate successful exploitation of the 'Open/Execute a file' action.
- Inspect PDFs for action objects containing unusually long filename paths, particularly relative or absolute paths in Open/Execute actions.
- Correlate network downloads of PDFs with subsequent Foxit Reader execution and any unexpected process creation on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0837 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0837), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.