Vulnerability record · CVE-2020-13557 · published 22 December 2020
CVE-2020-13557: Foxit PDF Reader JavaScript engine use-after-free
Foxitsoftware · Foxit Reader
Foxit PDF Reader 10.1.0.37527 contains a use-after-free in its JavaScript engine. A crafted PDF can cause reuse of freed memory, which the vendor and reporting researcher describe as leading to arbitrary code execution. The flaw matters because PDF readers are widely deployed and the trigger is a document users are accustomed to opening.
Description
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high EPSS and public exploit references, tempered by the requirement that a user open a malicious file.
What it is
Foxit PDF Reader 10.1.0.37527 contains a use-after-free in its JavaScript engine. A crafted PDF can cause reuse of freed memory, which the vendor and reporting researcher describe as leading to arbitrary code execution. The flaw matters because PDF readers are widely deployed and the trigger is a document users are accustomed to opening.
Impact
An attacker who gets the crafted file opened can execute arbitrary code in the context of the Foxit Reader process, giving full compromise of that user's session. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached by opening a malicious PDF, or by visiting a malicious site if the browser plugin extension is enabled. The vector is network-reachable with no privileges required, but user interaction (opening the file or visiting the page) is required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded. EPSS is high at 0.70388 (99.35th percentile), and both references are tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Foxit PDF Reader beyond 10.1.0.37527 to a current supported release.
- Disable or remove the Foxit browser plugin extension so web pages cannot invoke the reader.
- Block or quarantine untrusted PDF attachments at the mail and web gateway.
- Where feasible, restrict PDF opening to a sandboxed or isolated viewer.
- Track Foxit advisories for the fixed build and verify the installed version across endpoints.
Detection
- Alert on Foxit Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Monitor for Foxit Reader crashes or repeated restarts that may indicate memory corruption attempts.
- Hunt for PDFs delivered from external senders or newly registered domains that are opened shortly before suspicious process activity.
- Check endpoint telemetry for Foxit Reader loading unusual DLLs or writing executables to user-writable paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1171 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1171 | ExploitThird Party Advisory |
Track CVE-2020-13557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.