Junglewise Threat Intelligence

CVE-2026-57239: Foxit PDF Reader and Editor privilege escalation in update service

CVE-2026-57239 · Severity: high · CVSS 8.2 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are popular tools for viewing and modifying PDF documents. A security flaw in the update service allows a standard user to trick the software into running malicious files with the highest possible system permissions. If exploited, an attacker could gain full control over the computer, potentially leading to data theft or the installation of persistent malware.

Technical details

A local privilege escalation vulnerability exists in Foxit PDF Reader and Editor due to an uncontrolled search path (CWE-427) within the Foxit update service. The service executes user-controllable executable files or loads malicious DLLs with elevated privileges during the update check process. An attacker with local access can exploit this by placing a malicious file in a location searched by the high-privilege process, leading to code execution as NT AUTHORITY\SYSTEM. The vulnerability requires minimal user interaction (triggering an update check) and is fixed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-08: advisory

References