CVE-2025-13941: Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13941?
CVE-2025-13941 has been classified as a local privilege escalation vulnerability, which could allow attackers to gain higher-level permissions.
How do I fix CVE-2025-13941?
To address CVE-2025-13941, ensure that you are running the latest version of the Foxit PDF Reader/Editor Update Service, which includes the necessary security patches.
Who is affected by CVE-2025-13941?
Users of Foxit PDF Reader/Editor Update Service are affected by CVE-2025-13941 due to improper file system permissions during plugin installation.
What are the potential consequences of CVE-2025-13941?
If exploited, CVE-2025-13941 could allow a local attacker to elevate their privileges and execute unauthorized actions on the system.
How does CVE-2025-13941 exploit local privileges?
CVE-2025-13941 exploits local privileges by allowing an attacker with low-level access to modify or replace critical update service resources.