First published: Tue May 28 2024(Updated: )
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF Reader |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29072 has a low severity rating due to its nature as a privilege escalation vulnerability.
To fix CVE-2024-29072, update to the latest version of Foxit Reader that addresses this vulnerability.
CVE-2024-29072 affects users of Foxit Reader version 2024.2.0.25138 and potentially earlier versions.
CVE-2024-29072 is caused by improper certification validation of the updater executable in Foxit Reader.
CVE-2024-29072 requires user interaction, as a low privilege user must trigger the update action for exploitation.