VYPR
patchPublished Sep 23, 2026· 1 source

Foxit PDF Reader Vulnerable to Local Privilege Escalation via Improper Certificate Validation

A local privilege escalation vulnerability in Foxit PDF Reader's update component allows network-adjacent attackers to execute arbitrary code with SYSTEM privileges.

The Zero Day Initiative (ZDI) has disclosed a critical local privilege escalation vulnerability, tracked as ZDI-26-741 and assigned CVE-2026-91812, affecting Foxit PDF Reader. This flaw resides within the software's update functionality, specifically in how it handles server certificate validation. Network-adjacent attackers can exploit this weakness to execute arbitrary code with SYSTEM-level privileges on vulnerable systems.

The vulnerability requires user interaction for exploitation, meaning a victim must be tricked into visiting a malicious webpage or opening a specially crafted file. Once triggered, the attacker can leverage the improper certificate validation to bypass security checks and inject malicious code. The CVSS score for this vulnerability is rated at 7.1, indicating a high severity.

Foxit has acknowledged the vulnerability and has released an update to address the issue. Users are strongly advised to update their Foxit PDF Reader installations to the latest version to mitigate the risk of exploitation. Further details on the fix can be found on Foxit's official security bulletins page.

The disclosure timeline indicates that the vulnerability was initially reported to the vendor on August 20, 2026. Following coordinated public disclosure efforts, the advisory was released on September 23, 2026, with an update to the advisory on the same day. The vulnerability was discovered and reported by security researchers praydog and kmx00.

This vulnerability highlights a recurring theme in software security: the importance of robust validation mechanisms, especially for components that handle updates or external communications. Improper certificate validation can open the door to man-in-the-middle attacks or the execution of malicious payloads disguised as legitimate software updates.

While exploitation requires user interaction, the potential impact of gaining SYSTEM privileges is significant. Attackers could use this as a stepping stone to deploy ransomware, exfiltrate sensitive data, or further compromise the network. Organizations relying on Foxit PDF Reader should prioritize patching this vulnerability to protect their endpoints.

The ZDI advisory provides technical details for security professionals, outlining the specific conditions under which the vulnerability can be exploited. The focus on the update mechanism underscores the need for continuous security monitoring and prompt patching of all software components, not just those directly exposed to the internet.

As with many software vulnerabilities, the timely release of patches by vendors like Foxit is crucial. However, the effectiveness of these patches depends on their rapid deployment by end-users and organizations. The ZDI's coordinated disclosure model aims to balance responsible disclosure with providing timely information to defenders.

Synthesized by Vypr AI