CVE-2026-3775 is a local privilege escalation vulnerability (CWE-427) in an unspecified application's update service, which insecurely loads system libraries from user-writable directories. Rated High with a CVSS score of 7.8, this flaw allows a low-privileged local attacker to achieve arbitrary code execution with SYSTEM privileges due to low attack complexity and no user interaction. The potential impact includes complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB. The vulnerability has garnered minor community attention, with a few mentions on social media platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.2.2.24014CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 14.0.0.33046, <= 14.0.2.33402CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2023.1.0.15510, <= 2023.3.0.23028CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2024.1.0.23997, <= 2024.4.1.27687CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2025.1.0.27937, <= 2025.3.0.35737CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.