Vulnerability record · CVE-2021-34833 · published 4 August 2021
CVE-2021-34833: Foxit PDF Reader Annotation use-after-free allows code execution
Foxit · Pdf Reader
Foxit PDF Reader 11.0.0.49893 mishandles Annotation objects, performing operations on an object without first validating that it exists, which is a use-after-free (CWE-416). A remote attacker can trigger the flaw through a crafted PDF or web page, and successful exploitation runs code in the context of the current process. The record names only version 11.0.0.49893; no other affected or fixed versions are stated.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14023.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
Foxit PDF Reader 11.0.0.49893 mishandles Annotation objects, performing operations on an object without first validating that it exists, which is a use-after-free (CWE-416). A remote attacker can trigger the flaw through a crafted PDF or web page, and successful exploitation runs code in the context of the current process. The record names only version 11.0.0.49893; no other affected or fixed versions are stated.
Impact
An attacker gains arbitrary code execution with the privileges of the Foxit PDF Reader process, which can lead to full compromise of the user's session and data.
Attack surface
Reached when the target opens a malicious PDF file or visits a malicious page, so user interaction is required and no authentication is needed. The CVSS vector is local (AV:L) with UI:R, reflecting the file-open or page-visit trigger rather than a network service.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.95655, 99.868th percentile), indicating elevated likelihood of exploitation activity. References are vendor and Zero Day Initiative advisories only, with no public exploit tag.
What to do
- Update Foxit PDF Reader and PDF Editor to the latest version listed in Foxit's security bulletins, which is the only fix path given in the record.
- If immediate patching is not possible, restrict opening of untrusted PDFs and disable or limit JavaScript and annotation handling in the reader.
- Open PDFs from external sources in a sandboxed or isolated environment, or convert them to a safer format before viewing.
- Block or filter inbound PDF attachments at the mail and web gateway where policy allows.
Detection
- Monitor for Foxit PDF Reader process crashes or abnormal terminations, which can indicate a use-after-free trigger.
- Hunt for child processes spawned by FoxitPDFReader.exe or FoxitPDFEditor.exe, especially command shells or scripting hosts.
- Alert on PDF files written to temp or download directories that are immediately opened by Foxit, correlating with external email or web referrers.
- Review endpoint telemetry for memory-corruption exploitation patterns in Foxit processes, such as unexpected module loads or writes to executable memory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-915/ | Third Party AdvisoryVDB Entry |
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-915/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-34833 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34833), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.