CVE-2024-9245
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 22, 2024
Updated: Nov 29, 2024
CWE ID 732
Summary
CVE-2024-9245 is a local privilege escalation vulnerability affecting Foxit PDF Reader Update Service. The flaw arises from improper permission assignments on configuration files utilized by the service. For an attacker to succeed, they must initially gain the ability to execute low-privileged code on the victimized system. Once exploited, the vulnerability enables the attacker to escalate privileges and execute code with SYSTEM rights, significantly increasing the attacker's access and control on the targeted system. (ZDI-CAN-23966)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.