CVE-2023-40194: CWE-73: External Control of File Name or Path in Foxit Foxit Reader
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.
CVE-2023-40194: CWE-73: External Control of File Name or Path in Foxit Foxit Reader
Description
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- talos
- Date Reserved
- 2023-08-15T19:59:27.595Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 690a53272a90255b94da674f
Added to database: 11/4/2025, 7:25:27 PM
Last updated: 11/4/2025, 7:31:00 PM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2023-40395: An app may be able to access contacts in Apple iOS and iPadOS
UnknownCVE-2023-40391: An app may be able to disclose kernel memory in Apple iOS and iPadOS
UnknownCVE-2023-40390: An app may be able to access user-sensitive data in Apple macOS
MediumCVE-2023-40388: Safari may save photos to an unprotected location in Apple macOS
UnknownCVE-2023-40386: An app may be able to access Notes attachments in Apple macOS
UnknownActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.