CVE-2025-13941

HIGH

Foxit Pdf Editor < 13.2.1.23955 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
foxit/pdf_editor < 13.2.1.23955
foxit/pdf_reader < 2025.2.1.33197
Published Dec 19, 2025
Tracked Since Feb 18, 2026