CVE-2019-14215
Description
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A wild pointer access in Foxit PhantomPDF's xfa.event.rest JavaScript handler leads to a denial-of-service crash.
Vulnerability
A wild pointer access vulnerability exists in Foxit PhantomPDF before version 8.3.11. The issue occurs in the xfa.event.rest XFA JavaScript method, where improper memory management leads to dereferencing a dangling or otherwise invalid pointer. This affects Foxit PhantomPDF (now Foxit PDF Editor) versions prior to 8.3.11 on Windows. [1]
Exploitation
An attacker can trigger this vulnerability by convincing a user to open a specially crafted PDF file containing malicious XFA JavaScript. No authentication or special network position is required beyond delivering the file to the victim. Upon the user opening the file, the JavaScript code calls xfa.event.rest, which accesses the wild pointer and causes the application to crash. [1]
Impact
Successful exploitation results in a denial of service: the Foxit PhantomPDF application crashes. The crash may lead to loss of unsaved work and user frustration, but there is no evidence of code execution or data exfiltration from the available references. [1]
Mitigation
The vulnerability is fixed in Foxit PhantomPDF version 8.3.11. Users should update to this version or later. As per Foxit's security bulletin, updating to the latest version of Foxit PDF Editor (such as 2026.1.1/14.0.4) also addresses the issue. No workaround is documented. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Foxit/PhantomPDFdescription
- Range: <8.3.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.foxitsoftware.com/support/security-bulletins.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.