PDF-XChange Editor U3D File Parsing Vulnerability Discloses Sensitive Information
CVE-2025-6648

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6648?

A vulnerability exists in PDF-XChange Editor's processing of U3D files, which could enable remote attackers to disclose sensitive information. The flaw arises from inadequate validation of user-supplied data, allowing an attacker to read beyond the bounds of allocated memory. To exploit this vulnerability, the user must visit a malicious webpage or open a compromised U3D file. This could potentially allow the attacker to combine this vulnerability with others to execute arbitrary code within the application's process.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6648 : PDF-XChange Editor U3D File Parsing Vulnerability Discloses Sensitive Information