Vulnerability record · CVE-2020-13548 · published 10 February 2021
CVE-2020-13548: Foxit Reader PDF use-after-free allows code execution
Foxitsoftware · Foxit Reader
Foxit Reader 10.1.0.37527 contains a use-after-free (CWE-416) that a crafted PDF can trigger, leading to arbitrary code execution. The flaw matters because PDF readers are commonly used to open untrusted files, and successful exploitation gives the attacker code execution in the context of the reader process.
Description
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS and public exploit-tagged references, but no KEV listing or confirmed in-the-wild ransomware use.
What it is
Foxit Reader 10.1.0.37527 contains a use-after-free (CWE-416) that a crafted PDF can trigger, leading to arbitrary code execution. The flaw matters because PDF readers are commonly used to open untrusted files, and successful exploitation gives the attacker code execution in the context of the reader process.
Impact
An attacker who gets the malicious PDF opened can execute arbitrary code on the victim's system, with the CVSS vector indicating high confidentiality, integrity and availability impact.
Attack surface
Reached by tricking a user into opening a malicious PDF, or, if the browser plugin extension is enabled, by visiting a malicious site. The CVSS vector shows network attack, no privileges required, but user interaction required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.65804, 99.2nd percentile) and both references are tagged Exploit and Technical Description, indicating public technical detail and exploit information exist.
What to do
- Update Foxit Reader to a version later than 10.1.0.37527 from the vendor; the record does not list fixed versions, so confirm the current patched release with Foxit.
- Disable or remove the Foxit browser plugin extension to close the drive-by path.
- Enforce opening of untrusted PDFs only in a sandboxed or isolated viewer.
- Block or quarantine PDFs from untrusted sources at email and web gateways.
- Restrict execution and macro-like behavior from the reader process via application control where feasible.
Detection
- Monitor for Foxit Reader process crashes or abnormal child processes spawned from the reader.
- Hunt for PDF files matching known exploit indicators from the Talos TALOS-2020-1166 report.
- Alert on reader processes making unexpected network connections or writing executables to disk.
- Track endpoint telemetry for use-after-free style crash patterns in Foxit Reader versions at or below 10.1.0.37527.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1166 | ExploitTechnical DescriptionThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1166 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2020-13548 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13548), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.