CVE-2010-20010
Foxit PDF Reader <4.2.0.0928 - RCE
Title source: llmDescription
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by sud0 · pythonlocalwindows
https://www.exploit-db.com/exploits/15532
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16621
metasploit
WORKING POC
GREAT
by dookie, Sud0 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/foxit_title_bof.rb
References (6)
Scores
EPSS
0.0702
EPSS Percentile
91.3%
Classification
CWE
CWE-121
Status
draft
Timeline
Published
Aug 20, 2025
Tracked Since
Feb 18, 2026