CVE-2015-2789: Medium severity foxit reader vulnerability
Published Mar 30, 2015
·Updated
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
Affected Software
7 affected components
Foxitsoftware Foxit Reader=6.1
Foxitsoftware Foxit Reader=6.1.2
Foxitsoftware Foxit Reader=6.1.4
Foxitsoftware Foxit Reader=6.2
Foxitsoftware Foxit Reader=6.2.1
Foxitsoftware Foxit Reader=7.0
Foxitsoftware Foxit Reader=7.0.6
Remediation
Event History
Mar 30, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2789?
CVE-2015-2789 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2015-2789?
To fix CVE-2015-2789, update Foxit Reader to version 7.0.6.1126 or later.
3
Which versions of Foxit Reader are affected by CVE-2015-2789?
CVE-2015-2789 affects Foxit Reader versions from 6.1 to 7.0.6.1126.
4
What type of vulnerability is CVE-2015-2789?
CVE-2015-2789 is an unquoted Windows search path vulnerability.
5
Can local users exploit CVE-2015-2789?
Yes, local users can exploit CVE-2015-2789 to gain elevated privileges.