CVE-2024-32488: Foxit PDF Editor
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
Affected products
- Foxit PDF Editor: before 10.1.12.37872 (fixed in 10.1.12.37872); from 11.0.0, before 11.2.8.53842 (fixed in 11.2.8.53842); from 12.0.0, before 12.1.4.15400 (fixed in 12.1.4.15400); from 13.0.0, before 13.0.1.21693 (fixed in 13.0.1.21693); from 2023.1.0.15510, before 2023.3.0.23028 (fixed in 2023.3.0.23028)
- Foxit PDF Reader: before 2023.3.0.23028 (fixed in 2023.3.0.23028)
Published 2024-04-15. Last modified 2026-06-17.