Information Disclosure in PDF-XChange Editor due to U3D File Parsing
CVE-2025-6643

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6643?

The vulnerability exists in the way PDF-XChange Editor processes U3D file parsing, leading to potential information disclosure. Due to inadequate validation of user-supplied data, an attacker could exploit this flaw by convincing a user to visit a malicious webpage or open a compromised U3D file. Successful exploitation may permit the attacker to read past the bounds of allocated memory segments, resulting in the exposure of sensitive information. This issue, when combined with other vulnerabilities, could allow for further compromises within the user environment.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6643 : Information Disclosure in PDF-XChange Editor due to U3D File Parsing