CVE Vulnerabilities

CVE-2024-29072

Improper Certificate Validation

Published: May 28, 2024 | Modified: Jun 10, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References