CVE-2023-32664: Foxit PDF Reader

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.

Affected products

  • Foxit PDF Reader: version 12.1.2.15332 only

Published 2023-07-19. Last modified 2026-06-17.