CVE 8.8 HIGH

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability_CVE-2025-13941

8.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.

AI Analysis

Local privilege escalation vulnerability in Foxit PDF Reader/Editor Update Service due to incorrect file system permissions

Basic Information

ID CVE-2025-13941
Source Foxit
Published Dec 19, 2025 at 01:51
Modified Dec 19, 2025 at 02:30

Affected Product

Vendor Foxit Software Inc.
Product Foxit PDF Reader
Version Versions 2025.2.1 and earlier
Affected Versions Foxit Software Inc. Foxit PDF Reader Versions 2025.2.1 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 13.2.1 and eariler
Foxit Software Inc. Foxit PDF Editor Versions 2025.2.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 13.2.1 and eariler

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Foxit Software Inc.
Product Foxit PDF Reader/Editor
Version 2025.2.1 and earlier, 14.0.1 and earlier, 13.2.1 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.