Windows users need to update this software immediately

This application's security hole could allow a hacker to execute malicious code on a user's Windows computer remotely, potentially taking control.

Foxit Reader is one of the most popular software for reading and editing PDF files.

According to Bleeping Computer, Foxit Software said that about 650 million users from 200 countries are using the store's Foxit Reader, including large enterprise customers such as Google, Intel, Dell, NASDAQ, Chevron, British Airways. , HP, Lenovo and Asus.

Picture 1 of Windows users need to update this software immediately

Recently, Foxit Software released a security update to fix a high severity remote code execution (RCE) vulnerability affecting Foxit Reader.

Bleeping Computer said that this security vulnerability was discovered by Cisco Talos security expert Aleksandar Nikolic, which could allow attackers to execute malicious code on a user's Windows computer remotely and potentially hijack. control.

Picture 2 of Windows users need to update this software immediately

This critical vulnerability is the result of a "Use After Free" bug found in the V8 JavaScript engine, used by Foxit Reader to render dynamic forms and interactive document elements.

This error can lead to serious problems such as program crashes, data corruption, and allowing hackers to execute arbitrary code on a victim's computer running a vulnerable version of the software.

Picture 3 of Windows users need to update this software immediately

This security vulnerability is caused by the way Foxit Reader application and browser extensions handle certain types of annotations.

In this way, attackers can use them to create malicious PDFs that allow them to run arbitrary code through precise memory control.

'A specially crafted PDF document can trigger the reuse of previously free memory, which can result in arbitrary code execution,' says security expert Nikolic.

However, an attacker needs to trick users into opening a malicious file or website to trigger this vulnerability if the browser plugin extension is enabled.

Picture 4 of Windows users need to update this software immediately

It is known that the security vulnerability affects Foxit Reader version 10.1.3.37598 and earlier versions. This vulnerability has been fixed on Foxit Reader version 10.1.4.37651.

Users can download the latest version of Foxit Reader by clicking Check for Updates in the application's Help dialog.

Update 09 May 2021
Category

System

Mac OS X

Hardware

Game

Tech info

Technology

Science

Life

Application

Electric

Program

Mobile