CVE-2025-13941
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD
Description
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
Affected (6)
Products: Foxit: Pdf Editor, Pdf Reader
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 13.2.1.23955 | |
| Up to 2025.2.1.33197 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (1)
Source: 14984358-7092-470d-8f34-ade47a7658a2
Vendor Advisory
Timeline
No history available yet.