CVE-2024-29072

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1989 -

28 May 2024, 14:59

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-28 14:15

Updated : 2024-06-10 18:15


NVD link : CVE-2024-29072

Mitre link : CVE-2024-29072


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation