CVE-2026-3780
Untrusted Search Path in Installer Enables Local Privilege Escalation
Publication date: 2026-04-01
Last updated on: 2026-04-28
Assigner: Foxit
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| foxit | pdf_editor | From 2023.1.0.15510 (inc) to 2023.3.0.23028 (inc) |
| foxit | pdf_editor | From 2024.1.0.23997 (inc) to 2024.4.1.27687 (inc) |
| foxit | pdf_editor | to 13.2.2.24014 (inc) |
| foxit | pdf_editor | From 14.0.0.33046 (inc) to 14.0.2.33402 (inc) |
| foxit | pdf_editor | From 2025.1.0.27937 (inc) to 2025.3.0.35737 (inc) |
| foxit | pdf_reader | to 2025.3.0.35737 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-426 | The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs because the application's installer runs with elevated privileges but uses untrusted search paths to locate system executables and DLLs. These search paths can include directories writable by local users, allowing an attacker to place malicious binaries with the same names as legitimate system files. When the installer loads or executes these malicious binaries instead of the legitimate ones, it results in local privilege escalation.
How can this vulnerability impact me? :
The vulnerability can allow a local attacker to escalate their privileges on the affected system. By placing malicious binaries in user-writable directories that are searched by the installer, the attacker can have these binaries executed with elevated privileges. This can lead to unauthorized access, control over the system, and potentially full system compromise.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, users should update their Foxit PDF Reader and Editor applications to the latest versions.
Updates can be obtained through the application's built-in update feature or by downloading the latest versions from the Foxit website.