CVE-2024-32488: Foxit PDF Editor

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.

Affected products

  • Foxit PDF Editor: before 10.1.12.37872 (fixed in 10.1.12.37872); from 11.0.0, before 11.2.8.53842 (fixed in 11.2.8.53842); from 12.0.0, before 12.1.4.15400 (fixed in 12.1.4.15400); from 13.0.0, before 13.0.1.21693 (fixed in 13.0.1.21693); from 2023.1.0.15510, before 2023.3.0.23028 (fixed in 2023.3.0.23028)
  • Foxit PDF Reader: before 2023.3.0.23028 (fixed in 2023.3.0.23028)

Published 2024-04-15. Last modified 2026-06-17.