Impact
The vulnerability permits a local attacker to exploit the update service’s use of an uncontrolled search path, allowing a malicious DLL to be loaded with SYSTEM privileges and thus achieving arbitrary code execution, identified as CWE‑427.
Affected Systems
Foxit Software Inc.’s PDF Editor and PDF Reader applications on Windows are affected; the specific edition or version is not listed, so any installation that uses the default update service is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 and an EPSS below 1 % indicate high severity but low current exploitation likelihood; the flaw is not listed in the CISA KEV catalog, and exploitation requires local write access to the vulnerable directories and triggering an update check.
OpenCVE Enrichment