IT

Tracker / CVE-2026-3780

CVE-2026-3780

High 7.3

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

Affected products and versions

foxit pdf_editor · … → 13.2.2.24014
foxit pdf_editor · 14.0.0.33046 → 14.0.2.33402
foxit pdf_editor · 2023.1.0.15510 → 2023.3.0.23028
foxit pdf_editor · 2024.1.0.23997 → 2024.4.1.27687
foxit pdf_editor · 2025.1.0.27937 → 2025.3.0.35737
foxit pdf_reader · … → 2025.3.0.35737

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References