CVE-2025-66769
7.5Nitro · PDF Pro for Windows
A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted XFA packet.
Executive summary
Nitro PDF Pro for Windows v14.41.1.4 is vulnerable to a Denial of Service attack via a NULL pointer dereference, which allows unauthenticated remote attackers to crash the application.
Vulnerability
This vulnerability is a NULL pointer dereference flaw triggered when the application processes a malicious XFA packet. The attack is fully unauthenticated, as it requires no prior access or user interaction to trigger the service interruption.
Business impact
The exploitation of this vulnerability results in a Denial of Service, which can disrupt critical document processing workflows and business operations. With a CVSS score of 7.5, the vulnerability is classified as High severity due to its remote, unauthenticated nature and the ease with which an attacker can impact system availability.
Remediation
Immediate Action: Users should restrict access to PDF parsing services and monitor the vendor website for the release of a security update addressing this specific version.
Proactive Monitoring: Security teams should monitor system logs for application crashes and unusual packet patterns associated with XFA processing.
Compensating Controls: Organizations should employ network-level filtering to block unsolicited or untrusted PDF files containing XFA forms from reaching endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the potential for service disruption, administrators must treat this vulnerability with urgency. Although a patch is not currently listed, security teams should proactively isolate affected systems and verify that application-layer defenses are in place to mitigate the risk of remote DoS attacks.