CVE-2024-29072
HIGHFoxit PDF Editor < 11.2.9.53938 & PDF Reader < 2024.2.1.25153 Privilege Escalation
Title source: llmDescription
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1989
Exploit, Third Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1989
Scores
CVSS v3
8.2
EPSS
0.0006
EPSS Percentile
20.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (2)
foxit/pdf_editor
< 11.2.9.53938
foxit/pdf_reader
< 2024.2.1.25153
Published
May 28, 2024
Tracked Since
Feb 18, 2026