PDF-XChange Editor AcroForm Use-After-Free Vulnerability Exposes Users to Remote Code Execution Risks
CVE-2025-0899
8.8HIGH
Summary
The vulnerability in PDF-XChange Editor arises from improper handling of AcroForms, which fails to validate object existence before operations. This oversight allows remote attackers to execute arbitrary code if users visit a malicious page or open a harmful file. The flaw can lead to severe security breaches, compromising user systems and data integrity. To mitigate risks, users should apply patches as soon as available and exercise caution when opening documents from untrusted sources.
Affected Version(s)
PDF-XChange Editor 10.3.1.387
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved