PT-2025-52400 · Foxit · Foxit Pdf Reader/Editor

Hkpc

·

Published

2025-12-19

·

Updated

2026-01-29

·

CVE-2025-13941

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader/Editor (affected versions not specified)
Description A flaw exists in the Foxit PDF Reader/Editor Update Service related to file system permissions during plugin installation. Incorrect permissions assigned to resources used by the update service could allow a local attacker with limited privileges to modify or replace these resources. Subsequently, when the service executes these altered resources, it could lead to the execution of arbitrary code with SYSTEM privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-13941
ZDI-25-1173

Affected Products

Foxit Pdf Reader/Editor