PT-2025-52422 · Foxit · Foxit Pdf Reader

Published

2025-12-19

·

Updated

2025-12-24

·

CVE-2025-66494

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Reader versions prior to 2025.2.1 Foxit PDF Reader versions prior to 14.0.1 Foxit PDF Reader versions prior to 13.2.1
Description A use-after-free issue exists in the way Foxit PDF Reader processes PDF files. Specifically, a PDF object that is managed by multiple parent objects may be freed from memory while still being referenced. This situation could potentially allow a remote attacker to execute arbitrary code.
Recommendations Update Foxit PDF Reader to version 2025.2.1 or later. Update Foxit PDF Reader to version 14.0.1 or later. Update Foxit PDF Reader to version 13.2.1 or later.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-66494
ZDI-25-1175

Affected Products

Foxit Pdf Reader