CVE-2024-12753

Published: Dic 30, 2024 Last Modified: Ago 08, 2025 EU-VD ID: EUVD-2024-51088
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,7
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25408.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0002
Percentile
0,0th
Updated

EPSS Score Trend (Last 91 Days)

59

Improper Link Resolution Before File Access ('Link Following')

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Access Control Other
Potential Impacts:
Read Files Or Directories Modify Files Or Directories Bypass Protection Mechanism Execute Unauthorized Code Or Commands
Applicable Platforms
Operating Systems: Windows, Unix
View CWE Details
Application

Pdf Editor by Foxit

Version Range Affected
From 2023.1.0.15510 (inclusive)
To 2023.3.0.23028 (inclusive)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pdf Reader by Foxit

Version Range Affected
To 2024.3.0.26795 (inclusive)
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pdf Editor by Foxit

Version Range Affected
From 11.0.0 (inclusive)
To 11.2.11.54113 (inclusive)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pdf Editor by Foxit

Version Range Affected
From 2024.1.0.23997 (inclusive)
To 2024.3.0.26795 (inclusive)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pdf Editor by Foxit

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.8.15703 (inclusive)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pdf Editor by Foxit

Version Range Affected
From 13.0.0 (inclusive)
To 13.1.4.23147 (inclusive)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.foxit.com/support/security-bulletins.html
https://www.zerodayinitiative.com/advisories/ZDI-24-1739/