Lucene search

K
cve[email protected]CVE-2023-33240
HistoryMay 19, 2023 - 6:15 a.m.

CVE-2023-33240

2023-05-1906:15:08
web.nvd.nist.gov
95
cve-2023-33240
foxit pdf reader
foxit pdf editor
local privilege escalation
windows
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.

Affected configurations

NVD
Node
foxitpdf_editorRange10.1.11.37866
OR
foxitpdf_editorRange11.0.011.2.5.53785
OR
foxitpdf_editorRange12.0.012.1.1.15289
OR
foxitpdf_readerRange12.1.1.15289
AND
microsoftwindowsMatch-

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2023-33240