Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Vulnerability Description
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13941
Credits & Attribution
No credits recorded in the NVD database.
More from Foxit Software Inc.
View All →Affected Vendor
Foxit Software Inc.
View all reports →