Vulnerability record · CVE-2021-34847 · published 4 August 2021
CVE-2021-34847: Foxit PDF Reader Annotation use-after-free allows code execution
Foxit · Pdf Reader
Foxit PDF Reader 11.0.0.49893 fails to validate the existence of an Annotation object before operating on it, producing a use-after-free (CWE-416). A remote attacker can trigger the flaw through a crafted PDF or page, and successful exploitation runs code in the context of the current process. The record names only version 11.0.0.49893, so other affected versions are not specified here.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
Foxit PDF Reader 11.0.0.49893 fails to validate the existence of an Annotation object before operating on it, producing a use-after-free (CWE-416). A remote attacker can trigger the flaw through a crafted PDF or page, and successful exploitation runs code in the context of the current process. The record names only version 11.0.0.49893, so other affected versions are not specified here.
Impact
An attacker gains arbitrary code execution with the privileges of the Foxit process, which can lead to full compromise of the user's session and data. Because the flaw is in a document reader, it can be delivered through ordinary file or web content.
Attack surface
The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N): the target must open a malicious PDF or visit a malicious page. No authentication is needed, but the victim must take that action.
Exploitation
Not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded. EPSS is high (0.61554, 99.1st percentile), indicating elevated predicted likelihood, and references are vendor and ZDI advisories only, with no public exploit tag.
What to do
- Update Foxit PDF Reader and PDF Editor to the fixed release listed in Foxit's security bulletins; patch first.
- If immediate patching is not possible, restrict opening untrusted PDFs and disable or limit JavaScript and annotation handling where the product allows.
- Block or sandbox PDF handling for untrusted sources, and open untrusted documents in a low-privilege or isolated environment.
- Train users not to open unexpected PDF attachments or follow links to untrusted PDF content.
- Monitor Foxit vendor advisories for updated fixed versions covering products beyond the named 11.0.0.49893 build.
Detection
- Monitor for Foxit PDF Reader process crashes or abnormal terminations, which can accompany use-after-free exploitation.
- Alert on Foxit Reader spawning child processes such as cmd.exe, powershell.exe or script hosts, which is not normal for document viewing.
- Review endpoint telemetry for suspicious files opened by Foxit Reader from email clients, browsers or download directories.
- Track Foxit Reader versions in the estate and flag hosts still running 11.0.0.49893 or other unpatched builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-929/ | Third Party AdvisoryVDB Entry |
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-929/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-34847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.