HTTP: Foxit PDF Reader exportXFAData Method Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Foxit PDF Reader exportXFAData Method. A successful attack can lead to arbitrary code execution.

Extended Description

Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportXFAData method. The application exposes a JavaScript interface that allows writing arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19697.

Short Name
HTTP:STC:DL:FOXIT-EXPRT-DATA-CE
Severity
Major
Recommended
True
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-27363 Code Execution Foxit Method PDF Reader Remote exportXFAData
Release Date
05/16/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3702
False Positive
Unknown

Found a potential security threat?