High severity7.8NVD Advisory· Published Apr 1, 2026· Updated Apr 14, 2026
CVE-2026-3775
CVE-2026-3775
Description
The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.