Use-After-Free Vulnerability in Foxit PDF Reader and Editor on Windows
CVE-2025-66493
7.8HIGH
What is CVE-2025-66493?
A use-after-free vulnerability has been identified in the AcroForm handling within Foxit PDF Reader and Foxit PDF Editor on Windows systems, affecting versions prior to 2025.2.1, 14.0.1, and 13.2.1. This vulnerability occurs when a specially crafted PDF file containing JavaScript is opened, allowing an attacker to access freed memory, which may potentially lead to arbitrary code execution. Users are advised to update to the latest versions to mitigate these risks.
Affected Version(s)
Foxit PDF Editor Windows Versions 2025.2.1 and earlier
Foxit PDF Editor Windows Versions 14.0.1 and earlier
Foxit PDF Editor Windows Versions 13.2.1 and earlier
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anonymous working with Trend Micro Zero Day Initiative
