vulnerability

Foxit Reader: Improper Link Resolution Before File Access ('Link Following') (CVE-2021-38570)

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
Published
Aug 11, 2021
Added
Aug 16, 2021
Modified
Aug 16, 2021

Description

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.

Solution

foxit-reader-upgrade-10_1_4
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.