rootpwn

high · CVSS v3 8.8 · EPSS 0.00129

CVE-2026-91813

Foxit PDF Editor/Reader’s update mechanism contains a race condition that allows a local attacker to replace an update package between downl

Overview

Foxit PDF Editor/Reader’s update mechanism contains a race condition that allows a local attacker to replace an update package between download and extraction, enabling arbitrary code execution with elevated privileges. The flaw can be exploited on systems where Foxit is installed and updates are performed automatically.

Description

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.

Impact

Confidentiality, Integrity, and Availability are at risk: a local user with administrative privileges can gain full control of the affected system. Defenders should be aware that any user who can trigger an update may compromise the machine.

Remediation

Apply the vendor-supplied patch that enforces file locking and verifies the integrity of the update package before extraction. Disable automatic updates or configure the update client to use signed packages only. Monitor for anomalous update activity and restrict write permissions to the update directory.

Risk context

Severity is high (CVSS 8.8) but EPSS is low (0.00129), indicating a low probability of exploitation in the wild. Nonetheless, the high impact warrants prompt patching.

Affected products

  • Foxit PDF Editor
  • Foxit PDF Reader

Scores

Severity
high
CVSS v2
6.8
CVSS v3
8.8
CVSS v4
EPSS
0.00129

foxit pdf update local-privilege race-condition high-severity

← All CVEs