VulnerabilityModified
CVE-2015-2789
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
MEDIUM 4.4EPSS 3.19%
Does this matter?
Lower severity and a low EPSS score (3.19%). Track it; it rarely justifies an emergency change on its own.
Description
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.19% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- foxitsoftware/foxit reader
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130840/Foxit-Reader-7.0.6.1126-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/36390Exploit, Third Party Advisory, VDB Entry
- http://www.foxitsoftware.com/support/security_bulletins.php#FRD-25Patch, Vendor Advisory
- http://www.securityfocus.com/bid/73432
- http://www.securitytracker.com/id/1031879Third Party Advisory, VDB Entry
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5235.phpThird Party Advisory
- http://packetstormsecurity.com/files/130840/Foxit-Reader-7.0.6.1126-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/36390Exploit, Third Party Advisory, VDB Entry
- http://www.foxitsoftware.com/support/security_bulletins.php#FRD-25Patch, Vendor Advisory
- http://www.securityfocus.com/bid/73432
- http://www.securitytracker.com/id/1031879Third Party Advisory, VDB Entry
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5235.phpThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.