CVE-2026-3780
published 2026-04-01CVE-2026-3780: The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.12%
2.3th percentile
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.2.24014 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.2.33402 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_reader | <= 2025.3.0.35737 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jcq9-87h6-4wcr: The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-
ghsa_unreviewed·2026-04-01
CVE-2026-3780 [HIGH] CWE-426 GHSA-jcq9-87h6-4wcr: The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.
Citrix
Citrix Security Bulletin CTX140779
vendor_citrix·CVSS 7.5
CVE-2014-3780 [HIGH] Citrix Security Bulletin CTX140779
Citrix Security Bulletin CTX140779
CVE References: CVE-2014-3780, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-01
Published