Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2025-6641

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6641?

The vulnerability affects PDF-XChange Editor due to improper validation of user-supplied U3D file data. This flaw can be exploited by an attacker to gain access to sensitive information by enticing a user to open a maliciously crafted file or visit a compromised webpage. By leveraging this vulnerability, an attacker could potentially execute additional code within the context of the vulnerable software, ultimately leading to broader system exploitation.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6641 : Information Disclosure Vulnerability in PDF-XChange Editor