Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29072


A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.


Published

2024-05-28T14:15:12.493

Last Modified

2025-08-22T16:03:32.227

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application foxit pdf_editor ≤ 11.2.9.53938 Yes
Application foxit pdf_editor ≤ 12.1.6.15509 Yes
Application foxit pdf_editor ≤ 13.1.1.22432 Yes
Application foxit pdf_editor ≤ 2023.3.0.23028 Yes
Application foxit pdf_editor ≤ 2024.2.1.25153 Yes
Application foxit pdf_reader ≤ 2024.2.1.25153 Yes
Operating System microsoft windows - No

References