A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pdf_editor | Foxit | * | 13.2.1.23955 (including) |
| Pdf_editor | Foxit | 14.0.0.33046 (including) | 14.0.1.33197 (including) |
| Pdf_editor | Foxit | 2023.1.0.15510 (including) | 2023.3.0.23028 (including) |
| Pdf_editor | Foxit | 2024.1.0.23997 (including) | 2024.4.1.27687 (including) |
| Pdf_editor | Foxit | 2025.1.0.27937 (including) | 2025.2.1.33197 (including) |
| Pdf_reader | Foxit | * | 2025.2.1.33197 (including) |