CVE-2025-9330: Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Foxit Reader Update Service. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-25709.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9330?
CVE-2025-9330 is classified as a local privilege escalation vulnerability that can be exploited by local attackers.
How does CVE-2025-9330 affect Foxit PDF Reader?
CVE-2025-9330 allows local attackers to escalate their privileges on installations of Foxit PDF Reader.
What are the prerequisites for exploiting CVE-2025-9330?
An attacker must first gain the ability to execute low-privilege operations on the affected system to exploit CVE-2025-9330.
Is there a fix for CVE-2025-9330?
Yes, it is recommended to update Foxit PDF Reader to the latest version to mitigate CVE-2025-9330.
Who is affected by CVE-2025-9330?
Users of Foxit PDF Reader with vulnerable installations are affected by CVE-2025-9330.