PT-2026-56338 · Microsoft · Windows

·

CVE-2026-57239

·

Published

2026-03-25

·

Updated

2026-07-31

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader (affected versions not specified) Foxit PDF Editor (affected versions not specified)
Description A privilege escalation issue exists in the update service FoxitPDFReaderUpdater.exe due to an uncontrolled search path. This allows low-privilege users to place executable files in a location where they are directly executed by high-privilege processes, enabling the attacker to execute arbitrary code and elevate their privileges to NT AUTHORITYSYSTEM.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Untrusted Search Path

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10441
BDU:2026-10606
BDU:2026-10607
CVE-2026-57239

Affected Products

Windows