CVE-2025-13941
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-13941 is a local privilege escalation (LPE) vulnerability in the Foxit PDF Reader and Foxit PDF Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service, allowing a low-privileged local attacker to modify or replace those resources and have them executed by the service with SYSTEM privileges. The vulnerability was published on December 19, 2025, and affects multiple product version ranges including Foxit PDF Editor up to 13.2.1, 14.0.0–14.0.1, 2023.1.0–2023.3.0, 2024.1.0–2024.4.1, and 2025.1.0–2025.2.1, as well as Foxit PDF Reader up to 2025.2.1. It carries a CVSS v3.1 base score of 8.8 (High) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource). During plugin installation, the Foxit Update Service sets overly permissive file system ACLs on resources it later loads and executes, meaning a low-privileged local user can write to or replace those files before the service processes them — a classic "services file permissions weakness" (MITRE ATT&CK T1574.010). No user interaction is required, and the attack vector is local with low attack complexity, making exploitation straightforward for any authenticated local user. The changed scope in the CVSS vector reflects that the impact extends beyond the attacker's own privilege level to SYSTEM (ZDI Advisory).

Impact

Successful exploitation grants the attacker arbitrary code execution with SYSTEM-level privileges on the affected Windows host, resulting in complete compromise of confidentiality, integrity, and availability. An attacker who already has a low-privileged foothold (e.g., via phishing or another vulnerability) can use this flaw to fully take over the machine, disable security controls, install persistent backdoors, or pivot laterally within the network. All data on the system is at risk of exfiltration or destruction (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Gain local access: Obtain a low-privileged user account on a Windows system with Foxit PDF Reader or PDF Editor installed (e.g., via phishing, credential theft, or another vulnerability).
  2. Identify vulnerable installation: Confirm the installed version of Foxit PDF Reader/Editor falls within the affected ranges (e.g., PDF Editor ≤ 13.2.1, 14.0.0–14.0.1, 2023.x–2025.2.1, or PDF Reader ≤ 2025.2.1).
  3. Locate weakly-permissioned resources: Use tools such as icacls, accesschk (Sysinternals), or PowerShell to enumerate file system permissions on directories and files used by the Foxit Update Service, identifying resources writable by low-privileged users.
  4. Replace or modify the target resource: Overwrite or replace the identified file (e.g., a DLL, executable, or configuration file loaded by the update service) with a malicious payload (e.g., a reverse shell or backdoor binary).
  5. Trigger service execution: Wait for or trigger the Foxit Update Service to run (e.g., by initiating a plugin installation or update check), causing the service to load and execute the attacker-controlled file with SYSTEM privileges.
  6. Achieve SYSTEM-level code execution: The malicious payload executes in the context of the SYSTEM account, granting full control over the host (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected modification timestamps on files within the Foxit PDF Reader/Editor installation directory (especially DLLs or executables used by the update service); presence of unknown or unsigned binaries in Foxit installation paths.
  • Process: Unusual child processes spawned by the Foxit Update Service (e.g., cmd.exe, powershell.exe, mshta.exe, or network tools like curl, wget) running under the SYSTEM account.
  • Logs: Windows Event Log entries (Security log, Event ID 4688) showing process creation by the Foxit Update Service with unexpected child process names; System log entries indicating service restarts or failures around the time of file modification.
  • Network: Outbound connections from the Foxit Update Service process to unexpected external IP addresses or domains, particularly shortly after a plugin installation or update event.
  • Registry: New or modified scheduled tasks or services created under the SYSTEM account following Foxit update activity (ZDI Advisory).

Mitigation and workarounds

Foxit has released patches addressing this vulnerability; users should update Foxit PDF Reader and Foxit PDF Editor to the latest available versions beyond the affected ranges (i.e., beyond 2025.2.1 for PDF Reader and the respective fixed builds for PDF Editor). As interim mitigations, administrators should restrict local user write permissions on the Foxit installation directory using icacls or Group Policy, implement application whitelisting (e.g., Windows Defender Application Control) to prevent unauthorized binaries from executing, and monitor system logs for suspicious activity related to the Foxit Update Service. Limiting the number of users with local interactive access to systems running Foxit products also reduces the attack surface (Foxit Security Bulletins, ZDI Advisory).

Community reactions

Heise (a German technology publication) covered the vulnerability in an article titled "Foxit PDF Updates close highly risky security vulnerabilities," noting the high-severity nature of the flaw (Heise). The vulnerability was also highlighted in CISA's weekly vulnerability bulletin (SB25-356) and discussed in security community channels including Mastodon (TheHackerWire) and Bluesky. Community sentiment reflects moderate concern given the local-only attack vector, though the SYSTEM-level impact and PoC availability are noted as elevating risk for enterprise environments.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management