• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Commerce and Management Sciences World

Commerce, Financial Accounting, Human Resource Management,, Cost Accounting, Principles of Business

  • Subjects
    • Accounting
      • Financial Accounting
      • Cost Accounting
      • Accounting Information System
    • Principles of Banking
    • Introduction To Business
      • Introduction to Commerce
    • Auditing
    • Management
      • Principle of Management
      • Human Resource Management
      • Strategic Management
      • Organizational Behavior
      • Financial Management
      • Management Information System
    • Economics
    • Marketing
  • Miscellaneous
    • MCQs
      • Accounting MCQs
      • Auditing MCQs
    • Short Questions
You are here: Home / Miscellaneous / Using Foxit Reader? You might be vulnerable to network breaches 

Using Foxit Reader? You might be vulnerable to network breaches 

September 24, 2017 By Salman Qureshi

Cybersecurity and cyberattacks have become prominent topics lately. No matter how much you secure your network, vulnerabilities continue to emerge for different operating systems and applications. Most recently, security professionals have discovered two critical vulnerabilities in a third-party PDF reading application called Foxit Reader. These vulnerabilities allow hackers to execute arbitrarily-defined code on a user‘s computer when Foxit Reader is used without Safe Reading Mode enabled.

Using Foxit Reader? You might be vulnerable to network breaches

Two critical zero–day vulnerabilities

On August 17th, researchers Steven Seeley and Ariele Caltabiano discovered two vulnerabilities in Foxit Reader:

1. CVE-2017-10951, which acts as a command injection bug that resides in the app.launchURL function and executes strings provided by hackers. This vulnerability is mainly due to improper validation.

2. CVE-2017-10952, which exists in the saveAs function and allows hackers to execute an arbitrarily–specified file on user computers. If the arbitrary file is modified, then hackers can modify anything on the end user’s computer. Steven Seeley has tested a proof of concept and published it on Zero Day Initiative.

How can you keep Foxit Reader safe?

1.Take precautions: Avoid downloading attachments from email addresses you don’t know. Opening a PDF from a nefarious sender could compromise your entire system.

2.Manually change settings: Whether you’re using Foxit Reader or Foxit Phantom PDF, go to the settings menu and enable Safe Reading Mode and uncheck Enable JavaScript Actions.

3.Employ automatic patch management: Doing all the ground work manually is tiresome and complicated, especially since the number of vulnerabilities per application continually increases. Regularly updating your network is one of the best ways to remain free from zero-day vulnerabilities. Stay vigilant by employing patch management software like Desktop Central, which manages and deploys patches automatically.

How can ManageEngine help? 

ManageEngine offers two types of support for these Foxit Reader vulnerabilities:

1.Patch deployment

Desktop Central can patch Windows, Mac, Linux, and over 250 third-party applications, all from a central location. We have released an update specifically for Foxit products to automatically enable Safe Reading Mode in Foxit PDF applications.

2.Registry configuration

With Desktop Central, you can deploy specific registry configurations, including the Foxit-specific keys below, to managed computers.

Key for enabling Safe Reading Mode:
HKEY_CURRENT_USERSoftwareFoxit SoftwareFoxit Reader 8.0PreferencesTrustManager 
bSafeMode=1 (Enable Safe Reading Mode) 
bSafeMode=0 (Disable Safe Reading Mode) 

Key for unchecking Enable JavaScript Actions:
HKEY_CURRENT_USERSoftwareFoxit SoftwareFoxit Reader 8.0PreferencesOthers 
bEnableJS=1 (Enable JavaScript Actions) 
bEnableJS=0 (Disable JavaScript Actions) 
 

Start using Desktop Central today to evade vulnerabilities and breaches happening across any third–party application. 

Powered by Commerce Pk

Filed Under: Miscellaneous

The Mind Behind Commerce Pk

Salman Qureshi is Researcher & passionate Blogger, he loves to write on Commerce & Management Sciences subjects to assist students, Hope you guys will like his effort.




  • About Me
  • Privacy Policy
  • Copy Rights
  • Disclaimer
  • Publish Your Article
  • Contact Us
  • Discussion Forum
  • Ask Question

Copyright © 2025