← Vulnerability feed

Vulnerability record · CVE-2020-13548 · published 10 February 2021

CVE-2020-13548: Foxit Reader PDF use-after-free allows code execution

Foxitsoftware · Foxit Reader

Foxit Reader 10.1.0.37527 contains a use-after-free (CWE-416) that a crafted PDF can trigger, leading to arbitrary code execution. The flaw matters because PDF readers are commonly used to open untrusted files, and successful exploitation gives the attacker code execution in the context of the reader process.

8.8 CVSS 3.1 High EPSS 66% · top 0.8% CWE-416 · Use after free
8.8CVSS 3.1 base score, v2 6.8
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with high EPSS and public exploit-tagged references, but no KEV listing or confirmed in-the-wild ransomware use.

What it is

Foxit Reader 10.1.0.37527 contains a use-after-free (CWE-416) that a crafted PDF can trigger, leading to arbitrary code execution. The flaw matters because PDF readers are commonly used to open untrusted files, and successful exploitation gives the attacker code execution in the context of the reader process.

Impact

An attacker who gets the malicious PDF opened can execute arbitrary code on the victim's system, with the CVSS vector indicating high confidentiality, integrity and availability impact.

Attack surface

Reached by tricking a user into opening a malicious PDF, or, if the browser plugin extension is enabled, by visiting a malicious site. The CVSS vector shows network attack, no privileges required, but user interaction required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.65804, 99.2nd percentile) and both references are tagged Exploit and Technical Description, indicating public technical detail and exploit information exist.

What to do

  • Update Foxit Reader to a version later than 10.1.0.37527 from the vendor; the record does not list fixed versions, so confirm the current patched release with Foxit.
  • Disable or remove the Foxit browser plugin extension to close the drive-by path.
  • Enforce opening of untrusted PDFs only in a sandboxed or isolated viewer.
  • Block or quarantine PDFs from untrusted sources at email and web gateways.
  • Restrict execution and macro-like behavior from the reader process via application control where feasible.

Detection

  • Monitor for Foxit Reader process crashes or abnormal child processes spawned from the reader.
  • Hunt for PDF files matching known exploit indicators from the Talos TALOS-2020-1166 report.
  • Alert on reader processes making unexpected network connections or writing executables to disk.
  • Track endpoint telemetry for use-after-free style crash patterns in Foxit Reader versions at or below 10.1.0.37527.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1166 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1166 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2020-13548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38574Foxitsoftware foxit reader sql injection vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.EPSS 0.99%9.8CVE-2021-38568Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …EPSS 1.1%9.8CVE-2021-38572Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not v…EPSS 1.1%9.8CVE-2021-38573Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not val…EPSS 1.1%9.8CVE-2021-33793Foxitsoftware foxit reader out-of-bounds write vulnerabilityFoxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…EPSS 1.1%9.8CVE-2020-26534Foxitsoftware foxit reader use after free vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…EPSS 2.4%9.8CVE-2020-26535Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable…EPSS 1.7%9.8CVE-2020-26537Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-13548), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.