8.2

CVE-2024-29072

Exploit

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
FoxitPdf Editor Version <= 11.2.9.53938
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 12.0.0 <= 12.1.6.15509
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 13.0.0 <= 13.1.1.22432
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2024.1.0.23997 <= 2024.2.1.25153
   MicrosoftWindows Version-
FoxitPdf Reader Version <= 2024.2.1.25153
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.146
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
talos-cna@cisco.com 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.