« Volver al listado

CVE-2024-32488

Estado: AnalizadaAlta (7.8)—

In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-32488",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-32488",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-15T13:34:40.305398Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:foxit:pdf_reader:-:*:*:*:*:*:*:*"
          ],
          "vendor": "foxit",
          "product": "pdf_reader",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2023.3.0.23028"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:foxit:pdf_editor:11.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:foxit:pdf_editor:12.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "foxit",
          "product": "pdf_editor",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "11.2.8.53842"
            },
            {
              "status": "affected",
              "version": "12.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "12.1.4.15400"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:foxit:pdf_editor:13.0:*:*:*:*:*:*:*"
          ],
          "vendor": "foxit",
          "product": "pdf_editor",
          "versions": [
            {
              "status": "affected",
              "version": "13.0",
              "lessThan": "13.0.1.21693",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:foxit:pdf_editor:2023.0:*:*:*:*:*:*:*"
          ],
          "vendor": "foxit",
          "product": "pdf_editor",
          "versions": [
            {
              "status": "affected",
              "version": "2023.0",
              "versionType": "custom",
              "lessThanOrEqual": "2023.3.0.23028"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-15T06:15:07.863",
  "references": [
    {
      "url": "https://www.foxit.com/support/security-bulletins.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.foxit.com/support/security-bulletins.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-280"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there."
    },
    {
      "lang": "es",
      "value": "En Foxit PDF Reader and Editor anterior a 2024.1, la escalada de privilegios locales podría ocurrir durante las comprobaciones de actualización porque los permisos débiles en la carpeta del servicio de actualización permiten a los atacantes colocar archivos DLL manipulados allí."
    }
  ],
  "lastModified": "2026-06-17T07:29:43.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9D011A1-EE2D-4D61-B5B5-E862EBD88F8A",
              "versionEndExcluding": "10.1.12.37872"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1C6E513-5F37-4C0C-B079-F987E55CDDB7",
              "versionEndExcluding": "11.2.8.53842",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94EE6FF3-2762-417B-87C3-A212E655DC7B",
              "versionEndExcluding": "12.1.4.15400",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07D509A7-E4DB-4A8D-B8E1-4CF9F1FCC861",
              "versionEndExcluding": "13.0.1.21693",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EFD226E-D837-43CD-8FA3-501779AAB780",
              "versionEndExcluding": "2023.3.0.23028",
              "versionStartIncluding": "2023.1.0.15510"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B8CFDB3-13D5-45AD-9780-A97779F2392D",
              "versionEndExcluding": "2023.3.0.23028"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}