7.8
CVE-2026-91813
- EPSS 0.09%
- Veröffentlicht 23.09.2026 07:49:37
- Zuletzt bearbeitet 08.10.2026 14:01:22
- Erkennungen
Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version <= 13.2.5.63482
Foxit ≫ Pdf Editor Version >= 14.0.0.33046 <= 14.0.7.33751
Foxit ≫ Pdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
Foxit ≫ Pdf Editor Version >= 2024.1.0.23997 <= 2024.4.1.27687
Foxit ≫ Pdf Editor Version >= 2025.1.0.27937 <= 2025.3.0.35737
Foxit ≫ Pdf Editor Version >= 2026.1.0.36452 <= 2026.2.0.39747
Foxit ≫ Pdf Reader Version <= 2026.2.0.39747
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.005 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 14984358-7092-470d-8f34-ade47a7658a2 | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://www.foxit.com/support/security-bulletins.html