Share
## https://sploitus.com/exploit?id=A81ECB72-4197-5CE3-853D-12F31A93DCE0
# Foxit PDF Reader LPE

Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain `NT AUTHORITY\SYSTEM` rights via the Foxit PDF Reader updater service.

## Build

Just build the binary, drop it on your target and run it.

```
cargo build --release
```

## Usage

The program has three main entrypoints: `check`, `exploit` and `cleanup`. Arguments should be pretty clear 
what they do. By default `cleanup` is called after `exploit` by default, but in case some processes still 
have open handles you may want to run this as a separate command afterwards.

```
Usage: pdflpe.exe [OPTIONS] 

Commands:
  check    Check if the currently installed version of Foxit PDF Reader is vulnerable and exit
  exploit  Attempts to pop a SYSTEM shell using CVE-2026-3775/CVE-2026-3780/CVE-2026-57239
  cleanup  Clean up any possible artifacts from the exploitation process
  help     Print this message or the help of the given subcommand(s)

Options:
  -i, --install-dir      [default: "C:\\Program Files\\Foxit Software\\Foxit PDF Reader\\"]
  -t, --technique   [default: auto-detect] [possible values: auto-detect, win-spool-sideload, 
updater-link-sideload]
  -h, --help                   Print help
  -V, --version                Print version
```