7.8
CVE-2026-91803
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:13
- Zuletzt bearbeitet 08.10.2026 14:05:19
- Erkennungen
Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path Hijacking
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version <= 13.2.5.63482
Foxit ≫ Pdf Editor Version >= 14.0.0.33046 <= 14.0.7.33751
Foxit ≫ Pdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
Foxit ≫ Pdf Editor Version >= 2024.1.0.23997 <= 2024.4.1.27687
Foxit ≫ Pdf Editor Version >= 2025.1.0.27937 <= 2025.3.0.35737
Foxit ≫ Pdf Editor Version >= 2026.1.0.36452 <= 2026.2.0.39747
Foxit ≫ Pdf Reader Version <= 2026.2.0.39747
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.014 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 14984358-7092-470d-8f34-ade47a7658a2 | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
https://www.foxit.com/support/security-bulletins.html