logo

Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices

ID: 9f47fe45-cb57-51fa-b261-715c92181c72

STIX ID: report--9f47fe45-cb57-51fa-b261-715c92181c72

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Abinaya

...
...

Foxit PDF Reader contains a local privilege escalation vulnerability (CVE-2026-57239) in its updater/service architecture that allows an attacker with local access or an existing foothold to escalate to SYSTEM by sideloading malicious driver/DLL files and manipulating a writable FoxitData.txt (which the service decrypts using a hardcoded AES-128-CBC key). The report details reverse engineering findings, a working exploit chain that leverages the updater launched by the FoxitPDFReaderUpdateService.exe, detection indicators (unexpected .dll/.drv in AppData, modifications to FoxitData.txt, anomalous SYSTEM process launches), and recommends immediate patching to version 2026.2 plus application control and monitoring mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.