CVE-2026-57239: Escalating All The Privileges With Foxit PDF Reader
Attack Techniques & Methods2026-07-29, 11:16
CVE-2026-57239: Escalating All The Privileges With Foxit PDF Reader
Most local Windows LPEs require a complex exploitation chain. But sometimes all it takes is looking at how an application updates itself. Researcher Luke Paris (Paradoxis) discovered that the update mechanism of Foxit PDF Reader / PDF Editor allows a standard user to elevate privileges to
NT AUTHORITY\SYSTEM. The vulnerability was assigned the identifier CVE-2026-57239.During update checks, the Foxit service, running with elevated privileges, downloaded and executed binaries whose paths could be controlled by an unprivileged user. As a result, a trusted process effectively executed arbitrary code with
SYSTEM privileges.The vulnerability affects Foxit PDF Reader version 2026.1.1 and earlier, as well as several generations of Foxit PDF Editor (13.x, 14.x, 2023–2026). The fix was released as part of Foxit PDF Reader 2026.1.2 and the corresponding PDF Editor updates.
Vulnerabilities
Researchers
Vendors
Products