Vulnerabilities > CVE-2015-2789 - Local Privilege Escalation vulnerability in Foxit Reader

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
foxitsoftware
exploit available

Summary

Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. <a href="http://cwe.mitre.org/data/definitions/426.html">CWE-426: Untrusted Search Path</a>

Exploit-Db

descriptionFoxit Reader 7.0.6.1126 - Unquoted Service Path Elevation Of Privilege. CVE-2015-2789. Local exploit for windows platform
fileexploits/windows/local/36390.txt
idEDB-ID:36390
last seen2016-02-04
modified2015-03-16
platformwindows
port
published2015-03-16
reporterLiquidWorm
sourcehttps://www.exploit-db.com/download/36390/
titleFoxit Reader 7.0.6.1126 - Unquoted Service Path Elevation Of Privilege
typelocal