CVE-2025-69627
8.4Nitro Software · Nitro PDF Pro
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the this.mailDoc() JavaScript method, potentially leading to memory corruption and application crashes.
Executive summary
A heap use-after-free vulnerability in Nitro PDF Pro allows local attackers to trigger memory corruption and potential application crashes via a malicious PDF file.
Vulnerability
The vulnerability exists in the JavaScript method this.mailDoc(), where an internal XID object is freed prematurely while remaining in use by UI and logging functions. An attacker can trigger this condition by providing a specially crafted PDF that causes the software to reference stale memory, potentially leading to non-deterministic crashes or code execution.
Business impact
The flaw carries a CVSS score of 8.4, reflecting a high-severity risk to system integrity and availability. Successful exploitation could lead to unauthorized memory access or service disruption, which may impact business operations that rely on the software for document processing and management.
Remediation
Immediate Action: Users should restrict the opening of untrusted PDF files from unknown sources until a vendor-supplied patch is installed.
Proactive Monitoring: Security teams should monitor system logs for unusual application crashes or repeated error events associated with the Nitro PDF Pro process.
Compensating Controls: Deploy endpoint protection solutions configured to detect and block suspicious JavaScript execution within PDF readers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS severity, organizations should treat this vulnerability with urgency. Administrators must track vendor security bulletins for the release of a patch and prioritize its deployment once available to eliminate the risk of memory-based exploitation.