
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
Just build the binary, drop it on your target and run it.
cargo build --release
The program has three main entrypoints: check, exploit and cleanup. Arguments should be pretty clear
what they do. By default cleanup is called after exploit by default, but in case some processes still
have open handles you may want to run this as a separate command afterwards.
Usage: pdflpe.exe [OPTIONS] <COMMAND>
Commands:
check Check if the currently installed version of Foxit PDF Reader is vulnerable and exit
exploit Attempts to pop a SYSTEM shell using CVE-2026-3775/CVE-2026-3780/CVE-2026-57239
cleanup Clean up any possible artifacts from the exploitation process
help Print this message or the help of the given subcommand(s)
Options:
-i, --install-dir <PATH> [default: "C:\\Program Files\\Foxit Software\\Foxit PDF Reader\\"]
-t, --technique <TECHNIQUE> [default: auto-detect] [possible values: auto-detect, win-spool-sideload,
updater-link-sideload]
-h, --help Print help
-V, --version Print version