Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HDefault status
unaffected
Versions 2026.1 and earlier
affected
Versions 14.0.3 and earlier
affected
Default status
unaffected
Versions 2026.1 and earlier
affected
Description
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
Problem types
Product status
Versions 2026.1 and earlier
Versions 14.0.3 and earlier
Versions 2026.1 and earlier
Credits
Haein Lee from KAIST Hacking Lab
References
www.foxit.com/support/security-bulletins.html