CVE-2024-41605: Foxitsoftware Foxit PDF Editor

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.

Affected products

Published 2024-09-26. Last modified 2026-06-17.