CVE-2024-12753: Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25408.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12753?
CVE-2024-12753 is classified as a local privilege escalation vulnerability affecting Foxit PDF Reader.
How do I fix CVE-2024-12753?
To fix CVE-2024-12753, update your Foxit PDF Reader to the latest version provided by the vendor.
Who is affected by CVE-2024-12753?
CVE-2024-12753 affects users of Foxit PDF Reader on systems where an attacker can execute low-privileged code.
What are the potential impacts of CVE-2024-12753?
An attacker exploiting CVE-2024-12753 can escalate privileges and potentially take control of the affected system.
Is CVE-2024-12753 being actively exploited?
As of now, there are no reported active exploits for CVE-2024-12753, but users should remain vigilant.