A local privilege escalation vulnerability, tracked as CVE-2025-13941, has been identified in the Foxit PDF Reader Update Service. The flaw arises from incorrect file system permissions assigned to resources during plugin installation, allowing a local attacker with low privileges to modify or replace these resources. If exploited, the attacker could execute arbitrary code with SYSTEM privileges, significantly increasing the risk of full system compromise.
The vulnerability affects Foxit PDF Reader, and successful exploitation requires the attacker to have the ability to execute code with low privileges on the target system. Both the CVE advisory and the Zero Day Initiative confirm that the issue stems from the update service's mishandling of plugin resource permissions. The vulnerability was reported to Foxit in October 2025 and publicly disclosed in December 2025. Users are advised to consult Foxit's security bulletins for remediation steps and updates.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-13941 was publicly disclosed as a high-severity local privilege escalation vulnerability affecting Foxit PDF Reader/Editor. Advisories described that incorrect file system permissions during plugin installation could allow local resource modification or replacement and lead to arbitrary code execution with SYSTEM privileges.
A local privilege escalation flaw in the Foxit PDF Reader/Editor Update Service was reported to Foxit. The issue involved incorrect permissions on plugin-related resources that could let a low-privileged local attacker gain SYSTEM-level code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.