CVE detail
CVE-2021-21870 — CVE-2021-21870
Published 2021-08-05 · Modified 2026-06-17 · Vendor foxit · Product pdf_reader · Source nvd
HIGH
severity
CVSS-derived band
0.0190
EPSS probability
exploitation probability, 30d
78.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the browser plugin extension is enabled.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References