Advisory Details

December 15th, 2015

Foxit FoxitCloudUpdateService Local Privilege Escalation Vulnerability

ZDI-15-640
ZDI-CAN-3286

CVE ID CVE-2015-8843
CVSS SCORE 6.9, AV:L/AC:M/Au:N/C:C/I:C/A:C
AFFECTED VENDORS Foxit
AFFECTED PRODUCTS Foxit Reader
VULNERABILITY DETAILS


This vulnerability allows local attackers to elevate privileges on vulnerable installations of Foxit Reader. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the FoxitCloudUpdateService service. An attacker can trigger a memory corruption condition by writing certain data to a shared memory region. An attacker can leverage this vulnerability to execute code under the context of SYSTEM.

ADDITIONAL DETAILS Foxit has issued an update to correct this vulnerability. More details can be found at:
https://www.foxitsoftware.com/support/security-bulletins.php
DISCLOSURE TIMELINE
  • 2015-09-14 - Vulnerability reported to vendor
  • 2015-12-15 - Coordinated public release of advisory
CREDIT AbdulAziz Hariri of HP Zero Day Initiative and Jasiel Spelman of HP Zero Day Initiative
BACK TO ADVISORIES