CVE-2025-32451
8.8Foxit · Foxit Reader
A memory corruption vulnerability in Foxit Reader 2025.1.0.27937 allows arbitrary code execution via a malicious PDF file or browser plugin interaction.
Executive summary
A memory corruption vulnerability in Foxit Reader poses a critical risk of arbitrary code execution if a user interacts with a malicious PDF document or web content.
Vulnerability
The vulnerability arises from an uninitialized pointer (CWE-824). An unauthenticated attacker can trigger this flaw by enticing a user to open a crafted PDF document or visit a malicious website with the browser plugin enabled.
Business impact
The ability to achieve arbitrary code execution on a user workstation represents a severe threat to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the deployment of ransomware. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires prompt attention to prevent lateral movement within the network.
Remediation
Immediate Action: Users should immediately restrict the opening of untrusted PDF files and disable the Foxit Reader browser plugin until a vendor-supplied patch is installed.
Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process spawning behavior originating from the Foxit Reader application.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious memory access patterns or unauthorized shell commands associated with PDF reader processes.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The risk associated with this memory corruption flaw is significant due to the potential for arbitrary code execution. Organizations should prioritize identifying all instances of the affected version and apply vendor-provided security updates as soon as they become available. Until then, enforcing strict policies regarding the handling of external PDF documents is essential to mitigate the risk of compromise.
More Foxit CVEs
Sources
Originally found and disclosed by Discovered by KPC of Cisco Talos., per the CVE Program record.