Privilege Escalation Vulnerability in Foxit PDF Reader
CVE-2026-57239
What is CVE-2026-57239?
CVE-2026-57239 is a privilege escalation vulnerability identified in Foxit PDF Reader, a widely used software application for viewing, creating, and editing PDF documents. This vulnerability arises from the application's handling of user-controllable executable files, which can be executed by high-privilege processes. This scenario allows users with low privileges to potentially elevate their access to the NT AUTHORITY\SYSTEM level. Such an escalation poses a critical risk to organizations, as it could enable unauthorized users to execute arbitrary code, manipulate sensitive files, and compromise the overall integrity of the system.
The implications of this vulnerability can be particularly severe for organizations that rely on Foxit PDF Reader for document handling, as attackers could exploit this weakness to gain enhanced control over systems, leading to unauthorized data access or manipulation.
Potential impact of CVE-2026-57239
-
Unauthorized Access to System Resources: The exploitation of this vulnerability can allow low-privilege users to elevate their access rights, potentially granting them full control over the system. This could result in unauthorized access to critical system resources, leading to data theft or manipulation.
-
Increased Risk of Malware Deployment: With elevated privileges, attackers could deploy malware or ransomware onto affected systems, allowing for further network infiltration and spread of malicious activities within an organization.
-
Disruption of Business Operations: The ability to escalate privileges could disrupt business operations significantly, as compromised systems may become inoperable or unreliable. This may result in significant downtime, financial losses, and damage to the organization's reputation.
Affected Version(s)
Foxit PDF Editor Windows Versions 2026.1.1 and earlier
Foxit PDF Editor Windows Versions 14.0.4 and earlier
Foxit PDF Editor Windows Versions 13.2.4 and earlier
