Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
ID: 9f47fe45-cb57-51fa-b261-715c92181c72
STIX ID: report--9f47fe45-cb57-51fa-b261-715c92181c72
Feed Name: cybersecurityNews.com
Foxit PDF Reader contains a local privilege escalation vulnerability (CVE-2026-57239) in its updater/service architecture that allows an attacker with local access or an existing foothold to escalate to SYSTEM by sideloading malicious driver/DLL files and manipulating a writable FoxitData.txt (which the service decrypts using a hardcoded AES-128-CBC key). The report details reverse engineering findings, a working exploit chain that leverages the updater launched by the FoxitPDFReaderUpdateService.exe, detection indicators (unexpected .dll/.drv in AppData, modifications to FoxitData.txt, anomalous SYSTEM process launches), and recommends immediate patching to version 2026.2 plus application control and monitoring mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
