ZDI-CAN-28053: ZDI-25-1173: Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-13941.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28053?
The vulnerability ZDI-CAN-28053 has been assigned a CVSS rating that indicates a significant risk of privilege escalation.
How do I fix ZDI-CAN-28053?
To fix ZDI-CAN-28053, ensure that you update your Foxit PDF Reader to the latest version provided by the vendor.
Which software versions are affected by ZDI-CAN-28053?
ZDI-CAN-28053 affects installations of Foxit PDF Reader, specific version details should be checked with the vendor.
Who can exploit ZDI-CAN-28053?
ZDI-CAN-28053 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.
What types of attacks can ZDI-CAN-28053 facilitate?
ZDI-CAN-28053 can facilitate privilege escalation attacks that enable an attacker to gain unauthorized access to system resources.