
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
PoC-эксплойт для CVE-2026-3775/CVE-2026-3780 и CVE-2026-57239, который позволяет получить права NT AUTHORITY\SYSTEM через службу обновления Foxit PDF Reader.
Просто соберите бинарный файл, закиньте его на целевую систему и запустите.
cargo build --release
Программа имеет три основные точки входа: check, exploit и cleanup. Что делает каждый аргумент, должно быть вполне понятно. По умолчанию после exploit вызывается cleanup, но если у некоторых процессов всё ещё остаются открытые дескрипторы, вы можете запустить его позже отдельной командой.
Usage: pdflpe.exe [OPTIONS] <COMMAND>
Commands:
check Check if the currently installed version of Foxit PDF Reader is vulnerable and exit
exploit Attempts to pop a SYSTEM shell using CVE-2026-3775/CVE-2026-3780/CVE-2026-57239
cleanup Clean up any possible artifacts from the exploitation process
help Print this message or the help of the given subcommand(s)
Options:
-i, --install-dir <PATH> [default: "C:\\Program Files\\Foxit Software\\Foxit PDF Reader\\"]
-t, --technique <TECHNIQUE> [default: auto-detect] [possible values: auto-detect, win-spool-sideload,
updater-link-sideload]
-h, --help Print help
-V, --version Print version