Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcq9-87h6-4wcr

Опубликовано: 01 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

EPSS

Процентиль: 2%
0.00121
Низкий

7.3 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.3
nvd
6 месяцев назад

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

CVSS3: 7.3
fstec
6 месяцев назад

Уязвимость службы обновления программы для просмотра электронных документов в стандарте PDF Foxit PDF Reader (ранее Foxit Reader) и программы редактирования PDF-файлов Foxit PDF Editor (ранее Foxit PhantomPDF), позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 2%
0.00121
Низкий

7.3 High

CVSS3

Дефекты

CWE-426