PDF-XChange Editor U3D File Parsing Vulnerability Discloses Sensitive Information
CVE-2025-6648
3.3LOW
What is CVE-2025-6648?
A vulnerability exists in PDF-XChange Editor's processing of U3D files, which could enable remote attackers to disclose sensitive information. The flaw arises from inadequate validation of user-supplied data, allowing an attacker to read beyond the bounds of allocated memory. To exploit this vulnerability, the user must visit a malicious webpage or open a compromised U3D file. This could potentially allow the attacker to combine this vulnerability with others to execute arbitrary code within the application's process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PDF-XChange Editor 10.5.2.395
References
CVSS V3.0
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
