
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
إثبات مفهوم لاستغلال الثغرات CVE-2026-3775/CVE-2026-3780 و CVE-2026-57239 والتي تسمح لك بالحصول على صلاحيات NT AUTHORITY\SYSTEM عبر خدمة تحديث Foxit PDF Reader.
قم ببناء الملف الثنائي، ثم ضعه على الهدف وقم بتشغيله.
cargo build --release
يحتوي البرنامج على ثلاث نقاط دخول رئيسية: check و exploit و cleanup. يجب أن تكون الوسائط واضحة بما فيه الكفاية فيما تفعله. افتراضياً، يتم استدعاء cleanup بعد exploit، ولكن في حال كانت بعض العمليات لا تزال تحتوي على مقابض مفتوحة، فقد ترغب في تشغيل هذا كأمر منفصل لاحقاً.
Usage: pdflpe.exe [OPTIONS] <COMMAND>
Commands:
check Check if the currently installed version of Foxit PDF Reader is vulnerable and exit
exploit Attempts to pop a SYSTEM shell using CVE-2026-3775/CVE-2026-3780/CVE-2026-57239
cleanup Clean up any possible artifacts from the exploitation process
help Print this message or the help of the given subcommand(s)
Options:
-i, --install-dir <PATH> [default: "C:\\Program Files\\Foxit Software\\Foxit PDF Reader\\"]
-t, --technique <TECHNIQUE> [default: auto-detect] [possible values: auto-detect, win-spool-sideload,
updater-link-sideload]
-h, --help Print help
-V, --version Print version