PT-2024-7014 · Foxit · Foxit Pdf Reader+1
Patrick Nassef Henry
+1
·
Published
2024-05-15
·
Updated
2024-11-29
·
CVE-2024-9245
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foxit PDF Reader (affected versions not specified)
Foxit PDF Editor (affected versions not specified)
Description
This issue allows local attackers to escalate privileges on affected installations. The flaw exists within the handling of configuration files used by the Foxit Reader Update Service, resulting from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. The attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations
For Foxit PDF Reader, update to a version that fixes the incorrect permission assignment issue.
For Foxit PDF Editor, update to a version that fixes the incorrect permission assignment issue.
As a temporary workaround, consider restricting access to the Foxit Reader Update Service until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Default Permissions
Incorrect Permission
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Foxit Pdf Editor
Foxit Pdf Reader