8.1
CVE-2026-91812
- EPSS 0.08%
- Veröffentlicht 23.09.2026 07:49:51
- Zuletzt bearbeitet 08.10.2026 14:02:28
- Erkennungen
Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version <= 13.2.5.63482
Foxit ≫ Pdf Editor Version >= 14.0.0.33046 <= 14.0.7.33751
Foxit ≫ Pdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
Foxit ≫ Pdf Editor Version >= 2024.1.0.23997 <= 2024.4.1.27687
Foxit ≫ Pdf Editor Version >= 2025.1.0.27937 <= 2025.3.0.35737
Foxit ≫ Pdf Editor Version >= 2026.1.0.36452 <= 2026.2.0.39747
Foxit ≫ Pdf Reader Version <= 2026.2.0.39747
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.002 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 14984358-7092-470d-8f34-ade47a7658a2 | 7.9 | 1.2 | 6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://www.foxit.com/support/security-bulletins.html