A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
2024-05-28T14:15:12.493
2025-08-22T16:03:32.227
Analyzed
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | foxit | pdf_editor | ≤ 11.2.9.53938 | Yes |
Application | foxit | pdf_editor | ≤ 12.1.6.15509 | Yes |
Application | foxit | pdf_editor | ≤ 13.1.1.22432 | Yes |
Application | foxit | pdf_editor | ≤ 2023.3.0.23028 | Yes |
Application | foxit | pdf_editor | ≤ 2024.2.1.25153 | Yes |
Application | foxit | pdf_reader | ≤ 2024.2.1.25153 | Yes |
Operating System | microsoft | windows | - | No |