[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80167

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2015-2789

Date: (C)2015-04-01   (M)2017-12-07 


Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

CVSS Score: 4.4Access Vector: LOCAL
Exploit Score: 3.4Access Complexity: MEDIUM
Impact Score: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
SECTRACK-1031879
EXPLOIT-DB-36390
BID-73432
http://packetstormsecurity.com/files/130840/Foxit-Reader-7.0.6.1126-Privilege-Escalation.html
http://www.foxitsoftware.com/support/security_bulletins.php#FRD-25
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5235.php

CPE    1
cpe:/a:foxitsoftware:foxit_reader:6.1
OVAL    1
oval:org.secpod.oval:def:33778

© 2013 SecPod Technologies