PT-2024-24610 · Foxit · Foxit Pdf Reader/Editor
Published
2024-04-14
·
Updated
2025-07-09
·
CVE-2024-32488
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foxit PDF Reader and Editor versions prior to 2024.1
Description
The issue allows Local Privilege Escalation during update checks due to weak permissions on the update-service folder. This weakness enables attackers to place crafted DLL files in the folder, potentially leading to exploitation.
Recommendations
For versions prior to 2024.1, update to version 2024.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the update-service folder to prevent attackers from placing malicious DLL files.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Pdf Reader/Editor