TROYANOSYVIRUS
Back to CVEs

CVE-2026-3780

HIGH
7.3

Description

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

CVE Details

CVSS v3.1 Score7.3
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published4/1/2026
Last Modified4/1/2026
Sourcenvd
Honeypot Sightings0

Weaknesses (CWE)

CWE-426

References

https://www.foxit.com/support/security-bulletins.html(14984358-7092-470d-8f34-ade47a7658a2)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.