7.8
CVE-2024-9245
- EPSS 0.27%
- Veröffentlicht 22.11.2024 22:15:20
- Zuletzt bearbeitet 29.11.2024 18:21:03
- Erkennungen
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-23966.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor SwPlatform windows Version <= 11.2.10.53951
Foxit ≫ Pdf Editor SwPlatform windows Version >= 12.0 <= 12.1.7.15526
Foxit ≫ Pdf Editor SwPlatform windows Version >= 13.0 <= 13.1.3.22478
Foxit ≫ Pdf Editor SwPlatform windows Version >= 2023.0 <= 2023.3.0.23028
Foxit ≫ Pdf Editor SwPlatform windows Version >= 2024.0 <= 2024.2.3.25184
Foxit ≫ Pdf Reader SwPlatform windows Version <= 2024.2.3.25184
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.184 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Trend Micro | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://www.foxit.com/support/security-bulletins.html
https://www.zerodayinitiative.com/advisories/ZDI-24-1297/