← Vulnerability feed

Vulnerability record · CVE-2020-13557 · published 22 December 2020

CVE-2020-13557: Foxit PDF Reader JavaScript engine use-after-free

Foxitsoftware · Foxit Reader

Foxit PDF Reader 10.1.0.37527 contains a use-after-free in its JavaScript engine. A crafted PDF can cause reuse of freed memory, which the vendor and reporting researcher describe as leading to arbitrary code execution. The flaw matters because PDF readers are widely deployed and the trigger is a document users are accustomed to opening.

8.8 CVSS 3.1 High EPSS 70% · top 0.6% CWE-416 · Use after free
8.8CVSS 3.1 base score, v2 6.8
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with high EPSS and public exploit references, tempered by the requirement that a user open a malicious file.

What it is

Foxit PDF Reader 10.1.0.37527 contains a use-after-free in its JavaScript engine. A crafted PDF can cause reuse of freed memory, which the vendor and reporting researcher describe as leading to arbitrary code execution. The flaw matters because PDF readers are widely deployed and the trigger is a document users are accustomed to opening.

Impact

An attacker who gets the crafted file opened can execute arbitrary code in the context of the Foxit Reader process, giving full compromise of that user's session. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached by opening a malicious PDF, or by visiting a malicious site if the browser plugin extension is enabled. The vector is network-reachable with no privileges required, but user interaction (opening the file or visiting the page) is required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded. EPSS is high at 0.70388 (99.35th percentile), and both references are tagged Exploit, indicating public exploit detail exists.

What to do

  • Upgrade Foxit PDF Reader beyond 10.1.0.37527 to a current supported release.
  • Disable or remove the Foxit browser plugin extension so web pages cannot invoke the reader.
  • Block or quarantine untrusted PDF attachments at the mail and web gateway.
  • Where feasible, restrict PDF opening to a sandboxed or isolated viewer.
  • Track Foxit advisories for the fixed build and verify the installed version across endpoints.

Detection

  • Alert on Foxit Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
  • Monitor for Foxit Reader crashes or repeated restarts that may indicate memory corruption attempts.
  • Hunt for PDFs delivered from external senders or newly registered domains that are opened shortly before suspicious process activity.
  • Check endpoint telemetry for Foxit Reader loading unusual DLLs or writing executables to user-writable paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38574Foxitsoftware foxit reader sql injection vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.EPSS 0.99%9.8CVE-2021-38568Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …EPSS 1.1%9.8CVE-2021-38572Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not v…EPSS 1.1%9.8CVE-2021-38573Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not val…EPSS 1.1%9.8CVE-2021-33793Foxitsoftware foxit reader out-of-bounds write vulnerabilityFoxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…EPSS 1.1%9.8CVE-2020-26534Foxitsoftware foxit reader use after free vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…EPSS 2.4%9.8CVE-2020-26535Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable…EPSS 1.7%9.8CVE-2020-26537Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-13557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.