CVE-2026-3780
7.3Foxit Software Inc. · Foxit PDF Reader, Foxit PDF Editor
A local privilege escalation vulnerability exists in the Foxit installer due to an untrusted search path flaw, allowing local attackers to execute malicious binaries with elevated privileges.
Executive summary
A local privilege escalation vulnerability in the Foxit PDF Reader and Editor installer allows local attackers to execute arbitrary code with elevated system privileges.
Vulnerability
The application installer utilizes untrusted search paths to resolve system executables and DLLs, which allows a local attacker with standard user privileges to perform binary planting and achieve local privilege escalation.
Business impact
The vulnerability poses a high risk to organizational security, as it allows a standard local user to escalate their privileges to the level of the installer process. Successful exploitation could lead to full system compromise, unauthorized data access, and the bypass of security controls on affected workstations. The CVSS score of 7.3 reflects the high impact on confidentiality, integrity, and availability for local systems.
Remediation
Immediate Action: Monitor the Foxit security bulletin page for the release of a patched version and apply the update to all affected installations immediately.
Proactive Monitoring: Audit local workstation logs for unauthorized file creation or modifications within application installation directories and monitor for suspicious process execution patterns originating from installer-related paths.
Compensating Controls: Restrict write permissions on directories utilized by installers and ensure that standard users cannot place executable files in locations where the installer might search for dependencies.
Exploitation status
Public Exploit Available: No — there is no confirmation of a public exploit in the provided data.
Analyst recommendation
Given the potential for local privilege escalation, this vulnerability should be treated with high urgency. Organizations should identify all instances of the affected Foxit software within their environment and prepare to deploy the vendor-supplied patch as soon as it becomes available to prevent unauthorized access and potential system-wide compromise.
More Foxit Software Inc. CVEs
Sources
Originally found and disclosed by Kara Zaffarano, per the CVE Program record.