Unrated severityNVD Advisory· Published Dec 19, 2025· Updated Dec 19, 2025
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
CVE-2025-13941
Description
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
Affected products
3- Foxit Software Inc./Foxit PDF Editorv5Range: Versions 2025.2.1 and earlier
- Foxit Software Inc./Foxit PDF Readerv5Range: Versions 2025.2.1 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.