Security Advisory

CVE-2026-3780

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-01 01:40:33
Last updated 2026-04-02 02:14:27
Assigner Foxit
CVSS score 7.3
State PUBLISHED

Description

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.