CVE-2024-29072: High severity Foxit Reader vulnerability
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29072?
CVE-2024-29072 has a low severity rating due to its nature as a privilege escalation vulnerability.
How do I fix CVE-2024-29072?
To fix CVE-2024-29072, update to the latest version of Foxit Reader that addresses this vulnerability.
Who is affected by CVE-2024-29072?
CVE-2024-29072 affects users of Foxit Reader version 2024.2.0.25138 and potentially earlier versions.
What causes CVE-2024-29072?
CVE-2024-29072 is caused by improper certification validation of the updater executable in Foxit Reader.
Can CVE-2024-29072 be exploited remotely?
CVE-2024-29072 requires user interaction, as a low privilege user must trigger the update action for exploitation.