CVE-2024-29072: Foxit PDF Editor

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

Affected products

  • Foxit PDF Editor: up to and including 11.2.9.53938; from 12.0.0, up to and including 12.1.6.15509; from 13.0.0, up to and including 13.1.1.22432; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.2.1.25153
  • Foxit PDF Reader: up to and including 2024.2.1.25153

Published 2024-05-28. Last modified 2026-06-17.