
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
Prova di concetto di exploit per CVE-2026-3775/CVE-2026-3780 e CVE-2026-57239 che consente di ottenere i diritti NT AUTHORITY\SYSTEM tramite il servizio di aggiornamento di Foxit PDF Reader.
È sufficiente compilare il binario, copiarlo sul sistema target ed eseguirlo.
cargo build --release
Il programma ha tre punti di ingresso principali: check, exploit e cleanup. Gli argomenti dovrebbero rendere abbastanza chiaro cosa fanno. Di default cleanup viene chiamato dopo exploit, ma nel caso alcuni processi abbiano ancora handle aperti potresti voler eseguire questo comando separatamente in seguito.
Usage: pdflpe.exe [OPTIONS] <COMMAND>
Commands:
check Check if the currently installed version of Foxit PDF Reader is vulnerable and exit
exploit Attempts to pop a SYSTEM shell using CVE-2026-3775/CVE-2026-3780/CVE-2026-57239
cleanup Clean up any possible artifacts from the exploitation process
help Print this message or the help of the given subcommand(s)
Options:
-i, --install-dir <PATH> [default: "C:\\Program Files\\Foxit Software\\Foxit PDF Reader\\"]
-t, --technique <TECHNIQUE> [default: auto-detect] [possible values: auto-detect, win-spool-sideload,
updater-link-sideload]
-h, --help Print help
-V, --version Print version