Back to search
CVE-2011-10030
Published: Aug 20, 2025
Modified: May 15, 2026
PUBLISHED
Description
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next time the system boots or the user logs in.
| Vendor | Product | Versions |
|---|---|---|
Foxit Software | Foxit PDF Reader | affected 0 - < 4.3.1.0218 |
Weaknesses (CWE)
References
http://scarybeastsecurity.blogspot.com/2011/03/dangerous-file-write-bug-in-foxit-pdf.html
technical-description
exploit
https://www.foxit.com/pdf-reader/version-history.html
vendor-advisory
patch
https://www.vulncheck.com/advisories/foxit-pdf-reader-javascript-file-write
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now