7.3

CVE-2024-12753

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25408.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version >= 11.0.0 <= 11.2.11.54113
   Microsoft ≫ Windows Version -
Foxit ≫ Pdf Editor Version >= 12.0.0 <= 12.1.8.15703
   Microsoft ≫ Windows Version -
Foxit ≫ Pdf Editor Version >= 13.0.0 <= 13.1.4.23147
   Microsoft ≫ Windows Version -
Foxit ≫ Pdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
   Microsoft ≫ Windows Version -
Foxit ≫ Pdf Editor Version >= 2024.1.0.23997 <= 2024.3.0.26795
   Microsoft ≫ Windows Version -
Foxit ≫ Pdf Reader Version <= 2024.3.0.26795
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.193
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Trend Micro 6.7 0.8 5.9
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://www.foxit.com/support/security-bulletins.html
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-24-1739/
Third Party Advisory