CVE-2024-12753
Description
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25408.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Improper Link Resolution Before File Access ('Link Following')
DraftCommon Consequences
Applicable Platforms
Pdf Editor by Foxit
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Pdf Reader by Foxit
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
Pdf Editor by Foxit
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Pdf Editor by Foxit
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Pdf Editor by Foxit
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Pdf Editor by Foxit
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*