8.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
AI Analysis
Local privilege escalation vulnerability in Foxit PDF Reader/Editor Update Service due to incorrect file system permissions
Basic Information
ID
CVE-2025-13941
Source
Foxit
Published
Dec 19, 2025 at 01:51
Modified
Dec 19, 2025 at 02:30
Affected Product
Vendor
Foxit Software Inc.
Product
Foxit PDF Reader
Version
Versions 2025.2.1 and earlier
Affected Versions
Foxit Software Inc. Foxit PDF Reader Versions 2025.2.1 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 13.2.1 and eariler
Foxit Software Inc. Foxit PDF Editor Versions 2025.2.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 13.2.1 and eariler
Foxit Software Inc. Foxit PDF Reader Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 13.2.1 and eariler
Foxit Software Inc. Foxit PDF Editor Versions 2025.2.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 14.0.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 13.2.1 and eariler
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Foxit Software Inc.
Product
Foxit PDF Reader/Editor
Version
2025.2.1 and earlier, 14.0.1 and earlier, 13.2.1 and earlier