CVE-2009-0836
Foxit Reader <3.0.1506 - RCE
Title source: llmDescription
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.
Exploits (1)
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/pdf/foxit/authbypass.rb
References (9)
Scores
EPSS
0.1077
EPSS Percentile
93.2%
Classification
CWE
CWE-119
Status
draft
Affected Products (2)
foxitsoftware/reader
foxitsoftware/reader
Timeline
Published
Mar 10, 2009
Tracked Since
Feb 18, 2026