CVE-2026-3775: Foxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3775?
CVE-2026-3775 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2026-3775?
To mitigate CVE-2026-3775, users should ensure the Foxit PDF Editor and Reader are updated to the latest versions as released by Foxit.
Who is affected by CVE-2026-3775?
CVE-2026-3775 affects users of Foxit PDF Editor and Foxit Reader that utilize the update service.
What type of vulnerability is CVE-2026-3775?
CVE-2026-3775 is classified as a local privilege escalation vulnerability.
What is the impact of CVE-2026-3775?
The impact of CVE-2026-3775 allows low-privileged users to gain elevated privileges on the system.