Out-Of-Bounds Read Vulnerability in PDF-XChange Editor
CVE-2025-6642

7.8HIGH

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6642?

A vulnerability exists in PDF-XChange Editor due to improper parsing of U3D files, leading to an out-of-bounds read condition. This flaw allows remote attackers to execute arbitrary code if a user interacts with a maliciously crafted file or webpage. The insufficient validation of user-supplied data leads to potential reading past the allocated memory, making it possible for attackers to execute commands within the context of the affected process. Therefore, caution should be exercised when opening files from untrusted sources.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6642 : Out-Of-Bounds Read Vulnerability in PDF-XChange Editor