CVE-2024-29072

EUVD-2024-34436
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
talosCNA
8.2 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
foxitpdf_editor
𝑥
≤ 11.2.9.53938
foxitpdf_editor
12.0.0 ≤
𝑥
≤ 12.1.6.15509
foxitpdf_editor
13.0.0 ≤
𝑥
≤ 13.1.1.22432
foxitpdf_editor
2023.1.0.15510 ≤
𝑥
≤ 2023.3.0.23028
foxitpdf_editor
2024.1.0.23997 ≤
𝑥
≤ 2024.2.1.25153
foxitpdf_reader
𝑥
≤ 2024.2.1.25153
𝑥
= Vulnerable software versions