Rapid7

vulnerability

Foxit Reader: Multiple Interpretations of UI Input (CVE-2024-25858)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 5, 2024
Added
May 26, 2025
Modified
Apr 7, 2026

Description

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

Solution

foxit-reader-upgrade-2024_4
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.