← Back

CVE-2024-29072

nvd nist
Published: May 28, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: CNA (Secondary)

Description

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

Affected (6)

2 products
Pdf Editor
Pdf Reader
Configuration A
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Foxit
Up to 11.2.9.53938
From 12.0.0 to 12.1.6.15509
From 13.0.0 to 13.1.1.22432
From 2023.1.0.15510 to 2023.3.0.23028
From 2024.1.0.23997 to 2024.2.1.25153
Up to 2024.2.1.25153
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (4)

Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.