Foxit disclosed and patched CVE-2026-3775, a high-severity local privilege escalation vulnerability in the Foxit Reader/Editor Update Service that can let an authenticated low-privileged user execute code as SYSTEM. The flaw, tracked by the Zero Day Initiative as ZDI-26-251 and ZDI-CAN-28595, is an uncontrolled search path element issue (CWE-427) caused by the service loading libraries from unsecured locations, enabling DLL hijacking through malicious DLL planting.
The vulnerability carries a CVSS 7.8 rating and is considered particularly risky on shared Windows environments such as terminal servers, VDI, and multi-user workstations, where a standard user could elevate privileges without user interaction. Foxit released fixes across supported product branches, including versions such as 2026.1, 14.0.3, and 13.2.3, and defenders were urged to patch quickly, review writable DLL search-path locations, monitor for suspicious DLL files, and consider disabling the auto-update service until remediation is complete.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The Zero Day Initiative publicly disclosed CVE-2026-3775 / ZDI-26-251, describing a local privilege escalation vulnerability in Foxit PDF Reader caused by the update service loading a library from an unsecured location. The issue was credited to Erik Egsgard of Field Effect and assigned a CVSS score of 7.8.
Foxit remediated CVE-2026-3775, a DLL hijacking/uncontrolled search path flaw in the Foxit Reader/Editor Update Service that could let a low-privileged local attacker gain SYSTEM privileges. Reported fixed versions include 2026.1, 14.0.3, and 13.2.3 depending on product branch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.