ZDI-25-1173: Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-13941.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1173?
ZDI-25-1173 is classified with a CVSS rating indicating a significant risk of privilege escalation.
How do I fix ZDI-25-1173?
To mitigate ZDI-25-1173, update Foxit PDF Reader to the latest version provided by the vendor.
What type of attacks are possible due to ZDI-25-1173?
ZDI-25-1173 allows local attackers to escalate privileges on the affected systems.
What systems are affected by ZDI-25-1173?
ZDI-25-1173 affects installations of Foxit PDF Reader that have not been patched.
Can remote attackers exploit ZDI-25-1173?
No, ZDI-25-1173 requires that the attacker first have the ability to execute low-privileged code on the local system.