Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
References
Link | Resource |
---|---|
http://www.foxitsoftware.com/support/security_bulletins.php#FRD-25 | Patch Vendor Advisory |
http://www.exploit-db.com/exploits/36390 | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/130840/Foxit-Reader-7.0.6.1126-Privilege-Escalation.html | Exploit VDB Entry Third Party Advisory |
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5235.php | Third Party Advisory |
http://www.securitytracker.com/id/1031879 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/73432 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-03-30 07:59
Updated : 2016-12-02 19:06
NVD link : CVE-2015-2789
Mitre link : CVE-2015-2789
JSON object : View
CWE
Products Affected
foxitsoftware
- foxit_reader