Security readout for executives and security teams
Plain-English summary
Foxit Reader and PhantomPDF versions before 10.1.4 contain a file-handling flaw. A crafted workflow using extractPages could write to unintended files because the pathname was not validated. The source bundle does not provide CVSS, CWE, or exploit evidence.
Executive priority
Treat this as a targeted endpoint hygiene issue, not a confirmed emergency from the available evidence. Prioritize patch verification where Foxit is used for external PDFs, especially on business-critical or privileged workstations.
Technical view
CVE-2021-38572 is an arbitrary file write issue in Foxit Reader and PhantomPDF before 10.1.4. The described root cause is missing validation of the extractPages pathname. Public source data here does not define attack prerequisites, user interaction, privileges, impacted platforms, or confirmed exploitation.
Likely exposure
Exposure is limited to environments with Foxit Reader or PhantomPDF installed below version 10.1.4. Endpoint software inventories should be used to identify affected desktop installations. The provided affected-product metadata is incomplete beyond the CVE description.
Exploitation context
The CVE is not listed as KEV in the provided bundle, and no cited source claims active exploitation. The sources only establish the vulnerability class, affected product family, and fixed-version boundary.
Researcher notes
The record lacks CVSS, CWE, and detailed vendor advisory content in the supplied bundle. Analysis should avoid assumptions about exploitability beyond arbitrary file write via unvalidated extractPages pathname. Further vendor detail may refine prerequisites and impact.
Mitigation direction
- Upgrade Foxit Reader and PhantomPDF installations to 10.1.4 or later where applicable.
- Consult Foxit's security bulletin for the supported update path.
- Prioritize systems that handle untrusted or externally supplied PDF files.
- Remove unsupported Foxit installations if they cannot be upgraded.
Validation and detection
- Inventory endpoints for Foxit Reader and PhantomPDF installations.
- Confirm installed versions are 10.1.4 or later.
- Review software deployment records for missed or failed updates.
- Check whether high-risk users process externally supplied PDFs with Foxit.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-38572 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.foxitsoftware.com/support/security-bulletins.phpCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
