Executive brief
Foxit PDF Editor and Reader are document viewing and editing tools widely used in enterprise environments. An insecure permission configuration in the update daemon allows unprivileged local users to modify configuration files and execute arbitrary scripts with elevated system privileges, creating a clear path for privilege escalation attacks.
Technical details
A local privilege escalation vulnerability exists in the update daemon due to improper file permissions on its configuration file, allowing unprivileged users to modify it. An authenticated local attacker can exploit this to achieve arbitrary script execution with higher privileges. The vulnerability affects multiple versions of both Foxit PDF Editor and Reader on Windows and has been patched in version 2026.2.1 and later.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747, 2025.3.0.35737 and earlier, 2024.4.1.27687 and earlier, 2023.3.0.23028 and earlier, 14.0.7.33751 and earlier, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8