CVE-2026-3780
HIGHFoxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-3780. PoCs published by Paradoxis.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3780, a local privilege escalation (LPE) vulnerability in Foxit PDF Reader. The exploit leverages DLL side-loading techniques via the Foxit updater IPC mechanism to achieve SYSTEM privileges by impersonating a privileged process token.
Description
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.
Exploits (1)
This repository contains a functional exploit for CVE-2026-3780, a local privilege escalation (LPE) vulnerability in Foxit PDF Reader. The exploit leverages DLL side-loading techniques via the Foxit updater IPC mechanism to achieve SYSTEM privileges by impersonating a privileged process token.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H