CVE-2026-3780 Details
Description
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.
A vulnerability exists in Foxit PDF Reader and Foxit PDF Editor for Windows and Mac, specifically in versions through 2025.3.0.35737 for Reader and through 2025.3.0.69570 for Editor. The issue arises because the applications' installers, while running with elevated privileges, resolve system executables and DLLs from untrusted search paths that can include user-writable directories. This flaw enables local attackers to place malicious binaries with names matching those of legitimate system files, which are then loaded or executed instead of the authentic files, leading to local privilege escalation.
Users can update to Foxit PDF Reader 2026.1 or Foxit PDF Editor 2026.1, 14.0.3, or 13.2.3. Instructions for updating or downloading the latest versions are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.2.24014 >= 14.0.0.33046, <= 14.0.2.33402 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 |
CPE
Remediation
| |
| foxit pdf reader | <= 2025.3.0.35737 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | Foxit |