peter bassill · operator
$ cve CVE-2015-2789 JSON

CVE-2015-2789 EXPLOIT

4.4
MEDIUM · CVSS 2.0 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

Scoring

CVSS4.4 (MEDIUM, v2.0)
VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
EPSS3.19% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2015-03-30
Last modified2026-06-17

Affected (1)

VendorProduct
foxitsoftwarefoxit reader

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD