HIGH

CVE-2020-13560

CVSS v3

8.8

HIGH

EPSS Score

19.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Technical details

Published
12/22/2020

Frequently asked questions

What is CVE-2020-13560?

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Is CVE-2020-13560 actively exploited?

Active exploitation of CVE-2020-13560 has not been confirmed. The EPSS score is 19.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-13560?

CVE-2020-13560 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-13560 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.