IT

Tracker / CVE-2024-29072

CVE-2024-29072

High 8.2

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

Affected products and versions

foxit pdf_editor · … → 11.2.9.53938
foxit pdf_editor · 12.0.0 → 12.1.6.15509
foxit pdf_editor · 13.0.0 → 13.1.1.22432
foxit pdf_editor · 2023.1.0.15510 → 2023.3.0.23028
foxit pdf_editor · 2024.1.0.23997 → 2024.2.1.25153
foxit pdf_reader · … → 2024.2.1.25153

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References