Local Privilege Escalation in Foxit PDF Reader (CVE‑2026‑91813) via FoxitUpdater Race Condition
What It Is – A race‑condition flaw in the FoxitUpdater component of Foxit PDF Reader allows a low‑privileged attacker who can run code on a workstation to obtain SYSTEM‑level privileges.
Exploitability – The vulnerability is locally exploitable; an attacker must first achieve code execution as a standard user. CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploits are known, but the attack path is straightforward once foothold is gained.
Affected Products – Foxit PDF Reader (any version prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Patch & Vulnerability Management – Demonstrates the need for continuous, auditable patching processes; a missed update creates a high‑impact privilege‑escalation gap.
- Least‑Privilege Controls – Highlights the importance of enforcing least‑privilege on endpoint software and verifying that update mechanisms cannot be abused.
- Defensible Evidence – Timely remediation provides concrete evidence for auditors that the organization maintains an effective control‑assurance posture.
Recommended Actions
- Deploy Foxit’s September 2026 security update to all endpoints immediately.
- Verify the patch resolves the race‑condition through internal testing or vendor validation.
- Record the remediation in your patch‑management system and retain proof for audit trails.