CVE-2026-57239: Escalating All The Privileges With Foxit PDF Reader

CVE-2026-57239: Escalating All The Privileges With Foxit PDF Reader
Most local Windows LPEs require a complex exploitation chain. But sometimes all it takes is looking at how an application updates itself. Researcher Luke Paris (Paradoxis) discovered that the update mechanism of Foxit PDF Reader / PDF Editor allows a standard user to elevate privileges to NT AUTHORITY\SYSTEM. The vulnerability was assigned the identifier CVE-2026-57239.
During update checks, the Foxit service, running with elevated privileges, downloaded and executed binaries whose paths could be controlled by an unprivileged user. As a result, a trusted process effectively executed arbitrary code with SYSTEM privileges.
The vulnerability affects Foxit PDF Reader version 2026.1.1 and earlier, as well as several generations of Foxit PDF Editor (13.x, 14.x, 2023–2026). The fix was released as part of Foxit PDF Reader 2026.1.2 and the corresponding PDF Editor updates.
Vulnerabilities
8.2
CVE-2026-57239
Researchers
Luke Paris
Vendors
Foxit
Products
Foxit Pdf Editor
Foxit Pdf Reader