CVE-2026-3775Disclosure(foxit / pdf_editor)

LOWCVSS 7.8 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch foxit pdf_editor systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_editor
  • pdf_reader
  • windows

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked at 6 mentions on most recent observed day (2026-04-02)
  • 8 total mentions across 2 days

Affected systems

Products
pdf_editorpdf_readerwindows

1 version affected across 3 products

Deep dive

Activity timeline8 mentions / 2d
02356Mentions · 2026-04-01: 2Mentions · 2026-04-02: 6Patch / Workaround · 2026-04-02: 5Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 604-0104-02
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure1General1
2026-04-026
Disclosure4Patch2
Full discourse8 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-3775: DLL Hijacking in Foxit PDF Editor/Reader Update Service https://darkwebinformer.com/cve-2026-3775-dll-hijacking-in-foxit-pdf-editor-reader-update-service/

    Post summary

    The post announces a DLL hijacking vulnerability (CVE-2026-3775) affecting Foxit PDF Editor/Reader, but it does not provide exploit details, PoC, or patch information.

    0401034.4K
    218.4K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Foxit PDF Editor/Readerのアップデートサービスにローカル権限昇格の脆弱性。CVE-2026-3775はCVSSスコア7.8のDLLハイジャックで、古典的な検索順序ハイジャック。修正版提供済み。 https://darkwebinformer.com/cve-2026-3775-dll-hijacking-in-foxit-pdf-editor-reader-update-service/

    Post summary

    A local privilege escalation vulnerability (CVE‑2026‑3775) involving DLL hijacking in Foxit PDF Editor/Reader’s update service was disclosed, and a patch has already been released.

    00020796
    7.3K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** DLL Hijacking in Foxit PDF Editor/Reader Update Service (CVE-2026-3775) 🆔 **CVE-2026-3775** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: 2.121% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Versions prior to 2026.1 (includes PDF Editor 13.x <13.2.3, Editor 14.x <14.0.3) 🔧 **Fixed Versions:** PDF Editor/Reader 2026.1, PDF Editor 14.0.3, PDF Editor 13.2.3, PDF Reader 2026.1 🫨 **Attack Vectors:** - Local access (requires local logon) - DLL search-order hijacking / malicious DLL placement - Privilege escalation to SYSTEM - No user interaction required 📝 **Summary:** A local attacker with write access to directories in the Foxit update service search path can place a malicious DLL that the elevated update service will load, resulting in SYSTEM-level code execution. This enables full host compromise, persistence, lateral movement, and exposure of other users' data on shared systems. 📈 **Impact Scope:** Local attackers can achieve SYSTEM-level arbitrary code execution, enabling full host compromise, persistence, lateral movement, and access to other users' data on affected endpoints. 🛡️ **Recommended Actions:** - Apply vendor updates immediately to fixed versions (2026.1 / 14.0.3 / 13.2.3) - If patching is delayed, remove write permissions for non-admins from directories in the update service search path - Implement application allowlisting and monitor for anomalous DLL loads and suspicious service behavior - Audit and restrict service account privileges and filesystem ACLs; isolate and investigate any suspected compromises 🪢 **Related Resources:** - https://nvd.nist.gov/vuln/detail/CVE-2026-3775 - https://www.foxit.com/support/security-bulletins.html 🏷 **Tags:** #Cybersecurity #Foxit #DLLHijacking #PrivilegeEscalation

    Post summary

    CVE‑2026‑3775 is a DLL hijacking flaw in Foxit PDF update services that allows local attackers to gain SYSTEM‑level code execution; the advisory recommends immediate patching and filesystem permissions adjustments to mitigate the risk.

    0001064
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** DLL Hijacking in Foxit PDF Editor/Reader Update Service — CVE-2026-3775 📅 **Timeline:** Disclosure: 2026-04-01, Patch: 2026-03-31 🆔 **CVE-2026-3775** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: 2.121% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** PDF Editor/Reader versions prior to 2026.1, PDF Editor 14.x prior to 14.0.3, PDF Editor 13.x prior to 13.2.3 🔧 **Fixed Versions:** PDF Editor/Reader 2026.1, PDF Editor 14.0.3, PDF Editor 13.2.3 🫨 **Attack Vectors:** - Local DLL search-path hijacking in the updater (uncontrolled search paths include writable dirs) - Attacker with a standard account can place a malicious DLL in a writable directory expected by the updater - Update service runs elevated/System and may load the malicious DLL without user interaction - Low-complexity local privilege escalation to SYSTEM 📝 **Summary:** CVE-2026-3775 is a DLL search-path hijack in Foxit's update service that allows a local, low-privileged user to place a malicious DLL which the elevated updater may load, resulting in code execution as SYSTEM. Impact includes full local compromise, persistence, lateral movement and data exposure on shared workstations, terminal servers and VDI images. 📈 **Impact Scope:** Local privilege escalation to SYSTEM on affected Windows/macOS Foxit installations; enables full local compromise, persistence, lateral movement and exposure of other users' data on shared workstations, terminal servers and VDI images. 🛡️ **Recommended Actions:** - Apply vendor updates immediately — upgrade to PDF Editor/Reader 2026.1 or the listed fixed releases - Restrict write permissions on directories in the updater search path and enforce least privilege for update/service accounts 🪢 **Related Resources:** - https://nvd.nist.gov/vuln/detail/CVE-2026-3775 - https://www.foxit.com/support/security-bulletins.html 🏷 **Tags:** #Cybersecurity #Foxit #DLLHijacking

    Post summary

    CVE‑2026‑3775 is a local DLL hijacking flaw in Foxit PDF Product that can lead to SYSTEM-level execution; the vendor has released patches and users are advised to update and restrict updater permissions.

    0100080
    277 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** DLL Hijacking Local Privilege Escalation in Foxit PDF Editor/Reader Update Service (CVE-2026-3775) 📅 **Timeline:** Disclosure: 2026-04-01; fixes released (see fixed versions) 🆔 **CVE-2026-3775** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: 2.12% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Versions prior to 2026.1 (Editor/Reader ≤2025.3), Editor 13.x/14.x (older branches) 🔧 **Fixed Versions:** PDF Editor (Windows) 2026.1, PDF Editor (Windows) 14.0.3, PDF Editor (Windows) 13.2.3, PDF Editor/Reader (macOS) 2026.1, PDF Reader (Windows) 2026.1 🫨 **Attack Vectors:** - Local access — requires write access to directories in the update-service search path - DLL search-order hijacking (CWE-427) - No user interaction required; low complexity, leads to SYSTEM code execution 📝 **Summary:** A DLL search-order hijack in Foxit's update service allows a low-privileged local user to place a malicious DLL in a writable search path that the service loads as SYSTEM, enabling local privilege escalation and potential full host compromise. This is especially dangerous on shared workstations, terminal servers, and VDI where multiple users can write to searched directories. 📈 **Impact Scope:** Local privilege escalation to SYSTEM enabling arbitrary code execution, persistence, lateral movement, and access to other users' data; high risk in multi-user/shared environments. 🛡️ **Recommended Actions:** - Apply vendor updates to the fixed versions listed above - Restrict write permissions on directories in the update-service search path and enforce least privilege on user accounts/VDI hosts - Deploy EDR/monitoring for suspicious DLL loads and implement application allowlisting 🪢 **Related Resources:** - https://nvd.nist.gov/vuln/detail/CVE-2026-3775 - https://www.foxit.com/support/security-bulletins.html 🏷 **Tags:** #Cybersecurity #Foxit #DLLHijacking

    Post summary

    Foxit PDF Editor/Reader suffers from a DLL hijacking vulnerability (CVE‑2026‑3775) that allows local privilege escalation to SYSTEM, and the vendor has released patched versions. The advisory emphasizes applying updates and restricting write permissions.

    0000047
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Foxit PDF Reader Update Service — Uncontrolled Search Path Element LPE (CVE-2026-3775) 📅 **Timeline:** Disclosure: Not available; Patch: Not available 🆔 **CVE-2026-3775** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: 2.12% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Local low-privilege code execution on host - DLL search-order hijacking / uncontrolled search path - Requires ability to place a malicious library in an insecure location accessible to the service 📝 **Summary:** The Foxit Update Service may load libraries from uncontrolled locations, allowing a local low-privilege actor who can write a malicious DLL to gain SYSTEM-level execution. Successful exploitation results in full local privilege escalation and host compromise. 🛡️ **Recommended Actions:** - Apply the vendor update from Foxit immediately. - Restrict/remove unprivileged write access to directories the update service uses. - Run services with least privilege (avoid SYSTEM where unnecessary) and enable application allowlisting. - Hunt for suspicious DLL loads/new files in service paths and review EDR/endpoint logs; isolate hosts if patching is delayed. 🪢 **Related Resources:** - https://www.foxit.com/support/security-bulletins.html - https://www.cve.org/CVERecord?id=CVE-2026-3775 🏷 **Tags:** #Cybersecurity #FoxitPDF #LPE

    Post summary

    The post alerts to CVE‑2026‑3775’s LPE via DLL search-order hijacking in Foxit PDF Reader Update Service and urges immediate patching and mitigation steps.

    0000027
    277 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3775 📊 Severity: 7.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3775 #CVE-2026-3775 #CVE #High #CyberSecurity #InfoSec https://t.co/KBZTE2UOzK

    Post summary

    The tweet merely announces CVE-2026-3775 with a severity rating and provides a link to the NVD, offering no further technical or exploitation details.

    0000030
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3775 The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged user… https://www.cve.org/CVERecord?id=CVE-2026-3775

    Post summary

    The post references CVE‑2026‑3775, describing a flaw where the update service loads libraries from writable paths, indicating a potential vulnerability, but does not provide a PoC, exploit code, mitigation, or evidence of active exploitation.

    00000114
    56.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_editor---
Appfoxitpdf_reader---
OSmicrosoftwindows---

Explore more