CVE-2011-3691: Critical severity foxit reader vulnerability
Published Sep 27, 2011
·Updated
Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.
Affected Software
16 affected components
Foxitsoftware Foxit Reader<=5.0
Foxitsoftware Foxit Reader=2.0
Foxitsoftware Foxit Reader=2.2
Foxitsoftware Foxit Reader=2.3
Foxitsoftware Foxit Reader=3.0
Foxitsoftware Foxit Reader=3.1
Foxitsoftware Foxit Reader=3.1.1
Foxitsoftware Foxit Reader=3.1.3
Foxitsoftware Foxit Reader=3.1.4
Foxitsoftware Foxit Reader=3.2
Foxitsoftware Foxit Reader=3.2.1
Foxitsoftware Foxit Reader=3.3.1
Foxitsoftware Foxit Reader=4.0
Foxitsoftware Foxit Reader=4.1.1
Foxitsoftware Foxit Reader=4.2
Foxitsoftware Foxit Reader=4.3
Event History
Sep 27, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3691?
CVE-2011-3691 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2011-3691?
To fix CVE-2011-3691, upgrade to Foxit Reader version 5.0.2.0718 or later.
3
What types of files can exploit CVE-2011-3691?
CVE-2011-3691 can be exploited using Trojan horse files such as dwmapi.dll, dwrite.dll, or msdrm.dll placed in the working directory.
4
Is my version of Foxit Reader affected by CVE-2011-3691?
If you are using Foxit Reader versions prior to 5.0.2.0718, then you are affected by CVE-2011-3691.
5
Who is at risk from CVE-2011-3691?
Local users on systems running vulnerable versions of Foxit Reader are at risk from CVE-2011-3691.