CVE-2023-33240

HIGH

Foxit PDF Reader/E <12.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (2)
foxit/pdf_editor < 10.1.11.37866
foxit/pdf_reader < 12.1.1.15289
Published May 19, 2023
Tracked Since Feb 18, 2026