PDF-XChange Editor U3D File Parsing Vulnerability Discloses Sensitive Information
CVE-2025-6648
3.3LOW
What is CVE-2025-6648?
A vulnerability exists in PDF-XChange Editor's processing of U3D files, which could enable remote attackers to disclose sensitive information. The flaw arises from inadequate validation of user-supplied data, allowing an attacker to read beyond the bounds of allocated memory. To exploit this vulnerability, the user must visit a malicious webpage or open a compromised U3D file. This could potentially allow the attacker to combine this vulnerability with others to execute arbitrary code within the application's process.
Affected Version(s)
PDF-XChange Editor 10.5.2.395