Foxit PDF Editor and Reader contain a high-severity local privilege escalation flaw, tracked as CVE-2026-57239, that can let a standard Windows user gain NT AUTHORITY\SYSTEM privileges after achieving code execution on a device. The issue affects versions 2026.1.1 and earlier, 14.0.4 and earlier, and 13.2.4 and earlier, and stems from insecure updater behavior involving a user-writable AppData path, unsafe loading of winspool.drv, and a privileged update service, FoxitPDFReaderUpdateService.exe, that trusts a writable ProgramData control file.
Researchers reported that the service could be abused through manipulation of FoxitData.txt, with valid encrypted instructions crafted because the binary used AES-128-CBC with a hardcoded key. Public disclosure by researcher Luke Paris, along with a GitHub proof of concept, has lowered the barrier to exploitation even though no confirmed in-the-wild abuse has been reported. Foxit assigned the CVE and patched the vulnerability in version 2026.2; defenders are being urged to update quickly and watch for changes to FoxitData.txt, suspicious files in Foxit AppData directories, and unusual SYSTEM-level processes spawned by the Foxit update service.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Foxit remediated CVE-2026-57239 in version 2026.2 of its PDF software. Reporting states there was no confirmed in-the-wild exploitation at the time of disclosure.
Foxit assigned identifier CVE-2026-57239 to the privilege escalation vulnerability affecting Foxit PDF Editor/Reader. The flaw impacts versions 2026.1.1 and earlier, 14.0.4 and earlier, and 13.2.4 and earlier.
Researcher Luke Paris publicly disclosed the local privilege escalation vulnerability CVE-2026-57239 on the Paradoxis blog and released proof-of-concept code on GitHub. The disclosure described how Foxit update components could be abused to escalate from a local user context to NT AUTHORITY\SYSTEM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceblog.paradoxis.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.