Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Foxit Reader Update Service. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-25709.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory | 
| https://www.zerodayinitiative.com/advisories/ZDI-25-870/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    08 Sep 2025, 13:52
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* cpe:2.3:a:foxit:pdf_editor:2025.1.0.27937:*:*:*:*:*:*:* | |
| References | () https://www.foxit.com/support/security-bulletins.html - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-25-870/ - Third Party Advisory | |
| First Time | Microsoft Foxit pdf Reader Foxit pdf Editor Foxit Microsoft windows | 
02 Sep 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-02 21:15
Updated : 2025-09-08 13:52
NVD link : CVE-2025-9330
Mitre link : CVE-2025-9330
CVE.ORG link : CVE-2025-9330
JSON object : View
Products Affected
                foxit
- pdf_reader
- pdf_editor
microsoft
- windows
CWE
                
                    
                        
                        CWE-427
                        
            Uncontrolled Search Path Element
