high · CVSS v3 8.8 · EPSS 0.00129
CVE-2026-91813
Foxit PDF Editor/Reader’s update mechanism contains a race condition that allows a local attacker to replace an update package between downl
Overview
Foxit PDF Editor/Reader’s update mechanism contains a race condition that allows a local attacker to replace an update package between download and extraction, enabling arbitrary code execution with elevated privileges. The flaw can be exploited on systems where Foxit is installed and updates are performed automatically.
Description
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
Impact
Confidentiality, Integrity, and Availability are at risk: a local user with administrative privileges can gain full control of the affected system. Defenders should be aware that any user who can trigger an update may compromise the machine.
Remediation
Apply the vendor-supplied patch that enforces file locking and verifies the integrity of the update package before extraction. Disable automatic updates or configure the update client to use signed packages only. Monitor for anomalous update activity and restrict write permissions to the update directory.
Risk context
Severity is high (CVSS 8.8) but EPSS is low (0.00129), indicating a low probability of exploitation in the wild. Nonetheless, the high impact warrants prompt patching.
Affected products
- Foxit PDF Editor
- Foxit PDF Reader
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- 0.00129