Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
|
Tue, 23 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxit pdf Editor
Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Foxit pdf Editor
Microsoft Microsoft windows |
Fri, 19 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxit
Foxit pdf Reader Foxit reader Foxitsoftware Foxitsoftware foxit Pdf Editor Foxitsoftware pdf Reader |
|
| Vendors & Products |
Foxit
Foxit pdf Reader Foxit reader Foxitsoftware Foxitsoftware foxit Pdf Editor Foxitsoftware pdf Reader |
Fri, 19 Dec 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges. | |
| Title | Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Foxit
Published:
Updated: 2025-12-19T14:53:45.343Z
Reserved: 2025-12-03T01:32:27.232Z
Link: CVE-2025-13941
Updated: 2025-12-19T14:53:36.748Z
Status : Analyzed
Published: 2025-12-19T02:16:04.493
Modified: 2025-12-23T17:35:55.073
Link: CVE-2025-13941
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:15:24Z