CVE-2020-26540

HIGH

Foxit Reader & PhantomPDF <4.1 - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.foxitsoftware.com/support/security-bulletins.html

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 0.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-347
Status published
Products (2)
foxitsoftware/foxit_reader < 4.1
foxitsoftware/phantompdf < 4.1
Published Oct 02, 2020
Tracked Since Feb 18, 2026