Impact
The flaw permits a low‑privilege user to place an executable that is directly invoked by a high‑privilege PDF processing process. When the NT AUTHORITY\\SYSTEM, giving the attacker complete control over the machine and compromising confidentiality, integrity and availability.
Affected Systems
Foxit Software Inc. provides the vulnerable product, Foxit PDF Editor and Foxit PDF Reader. Affected versions are not specified in the CV any installed edition may be susceptible until patched.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity local privilege escalation, while the EPSS score of less than 1% reflects a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local: a low‑privilege user with filesystem access can create or embed a malicious executable in a PDF that the application will automatically execute under a high‑privilege process, granting SYSTEM privileges and full system compromise.
OpenCVE Enrichment