CVE-2025-55314

7.8

Foxit · PDF and Editor

A memory corruption vulnerability in Foxit PDF and Editor allows attackers to execute arbitrary code via specially crafted PDF files that trigger invalid memory access during JavaScript operations.

Executive summary

A critical memory corruption vulnerability in Foxit PDF and Editor for Windows and macOS poses a significant risk of arbitrary code execution for users who open malicious PDF files.

Vulnerability

The vulnerability arises when PDF pages are deleted via JavaScript, causing the application to fail to update internal states correctly. This leads to a use-after-free or invalid memory dereference during subsequent annotation management, which can be triggered by an unauthenticated attacker providing a malicious document.

Business impact

Successful exploitation of this flaw allows for arbitrary code execution on the host system, which could lead to a full compromise of the user workstation. Given the CVSS score of 7.8, this vulnerability is classified as High severity, posing a substantial risk to organizational data confidentiality, integrity, and availability.

Remediation

Immediate Action: Upgrade Foxit PDF and Editor to version 13.2 or 2025.2, or the latest available version provided by the vendor, to address the memory management flaw.

Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unexpected spikes in memory usage associated with the Foxit PDF process when handling document-intensive workflows.

Compensating Controls: Restrict the execution of JavaScript within PDF readers via Group Policy or application-level security settings to prevent the triggering of this vulnerability until updates can be deployed.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The risk of arbitrary code execution necessitates immediate action. Organizations should prioritize updating all instances of Foxit PDF and Editor within their environment to the latest patched releases to eliminate this attack vector. Failure to patch leaves systems vulnerable to weaponized documents designed to exploit these memory corruption flaws.

More Foxit CVEs

Sources