
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13941 is a local privilege escalation (LPE) vulnerability in the Foxit PDF Reader and Foxit PDF Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service, allowing a low-privileged local attacker to modify or replace those resources and have them executed by the service with SYSTEM privileges. The vulnerability was published on December 19, 2025, and affects multiple product version ranges including Foxit PDF Editor up to 13.2.1, 14.0.0–14.0.1, 2023.1.0–2023.3.0, 2024.1.0–2024.4.1, and 2025.1.0–2025.2.1, as well as Foxit PDF Reader up to 2025.2.1. It carries a CVSS v3.1 base score of 8.8 (High) (ZDI Advisory, Foxit Security Bulletins).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource). During plugin installation, the Foxit Update Service sets overly permissive file system ACLs on resources it later loads and executes, meaning a low-privileged local user can write to or replace those files before the service processes them — a classic "services file permissions weakness" (MITRE ATT&CK T1574.010). No user interaction is required, and the attack vector is local with low attack complexity, making exploitation straightforward for any authenticated local user. The changed scope in the CVSS vector reflects that the impact extends beyond the attacker's own privilege level to SYSTEM (ZDI Advisory).
Successful exploitation grants the attacker arbitrary code execution with SYSTEM-level privileges on the affected Windows host, resulting in complete compromise of confidentiality, integrity, and availability. An attacker who already has a low-privileged foothold (e.g., via phishing or another vulnerability) can use this flaw to fully take over the machine, disable security controls, install persistent backdoors, or pivot laterally within the network. All data on the system is at risk of exfiltration or destruction (ZDI Advisory, Foxit Security Bulletins).
icacls, accesschk (Sysinternals), or PowerShell to enumerate file system permissions on directories and files used by the Foxit Update Service, identifying resources writable by low-privileged users.cmd.exe, powershell.exe, mshta.exe, or network tools like curl, wget) running under the SYSTEM account.Foxit has released patches addressing this vulnerability; users should update Foxit PDF Reader and Foxit PDF Editor to the latest available versions beyond the affected ranges (i.e., beyond 2025.2.1 for PDF Reader and the respective fixed builds for PDF Editor). As interim mitigations, administrators should restrict local user write permissions on the Foxit installation directory using icacls or Group Policy, implement application whitelisting (e.g., Windows Defender Application Control) to prevent unauthorized binaries from executing, and monitor system logs for suspicious activity related to the Foxit Update Service. Limiting the number of users with local interactive access to systems running Foxit products also reduces the attack surface (Foxit Security Bulletins, ZDI Advisory).
Heise (a German technology publication) covered the vulnerability in an article titled "Foxit PDF Updates close highly risky security vulnerabilities," noting the high-severity nature of the flaw (Heise). The vulnerability was also highlighted in CISA's weekly vulnerability bulletin (SB25-356) and discussed in security community channels including Mastodon (TheHackerWire) and Bluesky. Community sentiment reflects moderate concern given the local-only attack vector, though the SYSTEM-level impact and PoC availability are noted as elevating risk for enterprise environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."