HomeFoxitCVE-2025-13941

CVE-2025-13941

HIGH
8.8CVSS
Published: 2025-12-19
Updated: 2025-12-23
AI Analysis

Description

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
low
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-732

Metadata

Primary Vendor
FOXIT
Published
12/19/2025
Last Modified
12/23/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

foxit : pdf_editorfoxit : pdf_editorfoxit : pdf_editorfoxit : pdf_editorfoxit : pdf_editorfoxit : pdf_reader

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-13941 | HIGH Severity | CVEDatabase.com | CVEDatabase.com