Vulnerability Details CVE-2022-25641
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.5%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2022-25641
-
cpe:2.3:a:foxit:pdf_editor:11.0.0
-
cpe:2.3:a:foxit:pdf_editor:11.0.0.49893
-
cpe:2.3:a:foxit:pdf_editor:11.0.1.0719
-
cpe:2.3:a:foxit:pdf_editor:11.1
-
cpe:2.3:a:foxit:pdf_editor:11.2.0.53415
-
cpe:2.3:a:foxit:pdf_editor:11.2.1
-
cpe:2.3:a:foxit:pdf_reader:11.0.0.49893
-
cpe:2.3:a:foxit:pdf_reader:11.0.1.0719
-
cpe:2.3:a:foxit:pdf_reader:11.0.1.49938
-
cpe:2.3:a:foxit:pdf_reader:11.1
-
cpe:2.3:a:foxit:pdf_reader:11.1.0.52543
-
cpe:2.3:a:foxit:pdf_reader:11.2.1
-
cpe:2.3:a:foxit:pdf_reader:11.2.1.53537
-
cpe:2.3:a:foxit:phantompdf:*
-
cpe:2.3:o:microsoft:windows:-