CVE-2026-3780

HIGH

Foxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-3780. PoCs published by Paradoxis.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3780, a local privilege escalation (LPE) vulnerability in Foxit PDF Reader. The exploit leverages DLL side-loading techniques via the Foxit updater IPC mechanism to achieve SYSTEM privileges by impersonating a privileged process token.

Description

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

Exploits (1)

github WORKING POC 5 stars
by Paradoxis · rustpoc
https://github.com/Paradoxis/CVE-2026-57239

This repository contains a functional exploit for CVE-2026-3780, a local privilege escalation (LPE) vulnerability in Foxit PDF Reader. The exploit leverages DLL side-loading techniques via the Foxit updater IPC mechanism to achieve SYSTEM privileges by impersonating a privileged process token.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Foxit PDF Reader <= 2026.2.0.36452
Auth required
Prerequisites: User-level access to the target system · Foxit PDF Reader installed in default or specified path · Ability to write to the updater directory (AppData\Roaming\Foxit Software\Continuous\Addon\Foxit PDF Reader\)
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (5)
foxit/pdf_editor < 13.2.2.24014
foxit/pdf_reader < 2025.3.0.35737
Foxit Software Inc./Foxit PDF Editor Versions 14.0.2 and earlier
Foxit Software Inc./Foxit PDF Editor Versions 2025.3 and earlier
Foxit Software Inc./Foxit PDF Reader Versions 2025.3 and earlier
Published Apr 01, 2026
Tracked Since Apr 01, 2026