First published: Mon Apr 15 2024(Updated: )
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PDF Reader | <2024.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32488 is classified as a local privilege escalation vulnerability.
To fix CVE-2024-32488, update the Foxit PDF Reader and Editor to version 2024.1 or later.
CVE-2024-32488 is caused by weak permissions on the update-service folder in earlier versions of Foxit PDF Reader and Editor.
Users of Foxit PDF Reader and Editor versions prior to 2024.1 are affected by CVE-2024-32488.
Attackers can exploit CVE-2024-32488 to place crafted DLL files in the update-service folder, potentially escalating their privileges.