Description
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.
Published: 2026-07-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw permits a low‑privilege user to place an executable that is directly invoked by a high‑privilege PDF processing process. When the NT AUTHORITY\\SYSTEM, giving the attacker complete control over the machine and compromising confidentiality, integrity and availability.

Affected Systems

Foxit Software Inc. provides the vulnerable product, Foxit PDF Editor and Foxit PDF Reader. Affected versions are not specified in the CV any installed edition may be susceptible until patched.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity local privilege escalation, while the EPSS score of less than 1% reflects a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local: a low‑privilege user with filesystem access can create or embed a malicious executable in a PDF that the application will automatically execute under a high‑privilege process, granting SYSTEM privileges and full system compromise.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update for Foxit PDF Editor or Foxit PDF Reader provided by Foxit Software.
  • If no patch is available, disable the PDF feature that allows automatic execution of user‑supplied executables or configure the application to whitelisting or exploit protection controls (e.g., AppLocker, Windows Defender Exploit Guard) to block execution of arbitrary binaries with SYSTEM privileges.
  • Follow the principle of least privilege by ensuring the PDF application is launched with the minimal rights needed for normal operation.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272

Thu, 23 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 21 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 16 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-676

Wed, 15 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-676

Tue, 14 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
CWE-94

Sun, 12 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
CWE-94

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-732

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Fri, 10 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-732

Thu, 09 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.
Title Foxit PDF Editor/Reader Local Privilege Escalation
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-09T03:55:40.047Z

Reserved: 2026-06-24T03:01:15.648Z

Link: CVE-2026-57239

cve-icon Vulnrichment

Updated: 2026-07-08T12:16:05.403Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses
  • CWE-272

    Least Privilege Violation