HIGH

CVE-2020-14425

CVSS v3

7.8

HIGH

EPSS Score

19.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.

Technical details

Published
11/2/2020

Frequently asked questions

What is CVE-2020-14425?

Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.

Is CVE-2020-14425 actively exploited?

Active exploitation of CVE-2020-14425 has not been confirmed. The EPSS score is 19.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-14425?

CVE-2020-14425 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2020-14425 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.