Use-After-Free Vulnerability in Foxit PDF and Editor for Windows
CVE-2025-55308

6.7MEDIUM

Key Information:

Vendor

Foxit

Vendor
CVE Published:
11 December 2025

What is CVE-2025-55308?

A vulnerability exists in Foxit PDF and Editor for Windows, where a specially crafted PDF file containing JavaScript can trigger a use-after-free condition. By invoking the closeDoc() function while internal objects remain in use, the software may inadvertently release these objects. This memory corruption flaw could potentially lead to information disclosure when the affected PDF is processed, posing risks to sensitive data managed by the application.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.