CVE-2026-57257
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-57257 is an out-of-bounds read vulnerability in Foxit PDF Reader and PDF Editor that occurs during PRC (Product Representation Compact) file parsing. Due to insufficient boundary verification for the PRC entity index, the application reads beyond the intended entity array bounds, resulting in an application crash. Affected products include Foxit PDF Reader (versions 2026.1.1 and earlier) and Foxit PDF Editor (versions 2026.1.1, 14.0.4, 13.2.4, and earlier across multiple release branches). The vulnerability was published on July 8, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read): during the PRC parsing stage, the application fails to validate that a PRC entity index falls within the bounds of the entity array before performing a read operation. An attacker can craft a malicious PRC file with an out-of-range entity index that, when parsed by the application, triggers a read past the end of the allocated buffer. Exploitation requires local access and user interaction — specifically, a victim must open the malicious file. The attack complexity is low, and no special privileges are required (GitHub Advisory, Foxit Security Bulletins).

Impact

Successful exploitation causes the Foxit PDF Reader or PDF Editor application to crash, resulting in a denial of service for the affected user. The CVSS scoring also indicates a low confidentiality impact, suggesting that the out-of-bounds read may expose limited amounts of memory content, though the primary consequence is availability loss. There is no integrity impact, and the scope is limited to the affected application without evidence of lateral movement potential (GitHub Advisory).

Exploitation steps

  1. Craft a malicious PRC file: Create a specially crafted PRC (Product Representation Compact) file containing a PRC entity index value that exceeds the bounds of the entity array, bypassing the missing boundary check.
  2. Deliver the file to the target: Use social engineering, phishing, or other means to deliver the malicious PRC file to a victim who has Foxit PDF Reader or PDF Editor installed.
  3. Induce user interaction: Convince the victim to open the malicious file with the vulnerable Foxit application (e.g., by embedding it in a PDF or presenting it as a legitimate document).
  4. Trigger the out-of-bounds read: When the application parses the PRC content, the missing boundary verification causes it to read beyond the entity array, resulting in an application crash (denial of service) and potentially exposing limited memory contents (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited PRC files (.prc extension) in user download directories, email attachments, or temporary folders.
  • Logs: Application crash logs or Windows Event Viewer entries showing Foxit PDF Reader/Editor process termination (e.g., application fault entries referencing FoxitPDFReader.exe or FoxitPDFEditor.exe).
  • Process: Abnormal termination of Foxit PDF Reader or Editor processes shortly after opening a PRC-containing file, potentially generating crash dump files (.dmp) in the application's crash reporting directory.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability. Users should update Foxit PDF Reader and PDF Editor to versions beyond 2026.1.1 (for the 2026 branch), beyond 14.0.4 (for the 14.x branch), and beyond 13.2.4 (for the 13.x branch) via the Foxit security bulletins page. As a workaround, users should avoid opening PRC files from untrusted or unknown sources, and administrators can restrict access to PRC file processing in managed environments (Foxit Security Bulletins, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management