CVE-2025-13941

8.8

Foxit Software Inc. · Foxit PDF Reader and Foxit PDF Editor

A local privilege escalation vulnerability in the Foxit PDF Reader/Editor Update Service allows low-privileged users to execute arbitrary code with SYSTEM privileges via file permission manipulation.

Executive summary

A critical local privilege escalation vulnerability in the Foxit PDF Reader and Editor Update Service allows a low-privileged attacker to gain full SYSTEM control over the affected host.

Vulnerability

This vulnerability (CWE-732) arises from incorrect file system permissions assigned to resources during plugin installation. A local attacker with low privileges can modify or replace these resources, which the update service subsequently executes with SYSTEM privileges.

Business impact

The ability for a local user to escalate privileges to the SYSTEM level poses a severe risk to the entire organization. Successful exploitation allows an attacker to bypass all OS security controls, potentially leading to full system compromise, data theft, and the installation of persistent malicious software. With a CVSS score of 8.8, this vulnerability represents a high-severity threat to any environment where these applications are deployed.

Remediation

Immediate Action: Monitor the official Foxit security bulletin page for the release of a patched version and apply the update to all instances of Foxit PDF Reader and Editor across the enterprise immediately.

Proactive Monitoring: Review system logs for unauthorized modifications to installation directories or unexpected executions originating from the Foxit Update Service process.

Compensating Controls: Restrict write permissions on the installation directories for the Foxit update service to administrative users only, preventing non-privileged users from modifying the vulnerable resources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise, this vulnerability must be addressed with high urgency. Administrators should prioritize the deployment of vendor-supplied patches as soon as they become available and implement strict file system controls to restrict access to update service resources in the interim.

More Foxit Software Inc. CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written

Sources