Use-After-Free Vulnerability in Foxit PDF Reader and Editor on Windows
CVE-2025-66493

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
19 December 2025

What is CVE-2025-66493?

A use-after-free vulnerability has been identified in the AcroForm handling within Foxit PDF Reader and Foxit PDF Editor on Windows systems, affecting versions prior to 2025.2.1, 14.0.1, and 13.2.1. This vulnerability occurs when a specially crafted PDF file containing JavaScript is opened, allowing an attacker to access freed memory, which may potentially lead to arbitrary code execution. Users are advised to update to the latest versions to mitigate these risks.

Affected Version(s)

Foxit PDF Editor Windows Versions 2025.2.1 and earlier

Foxit PDF Editor Windows Versions 14.0.1 and earlier

Foxit PDF Editor Windows Versions 13.2.1 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous working with Trend Micro Zero Day Initiative
.
CVE-2025-66493 : Use-After-Free Vulnerability in Foxit PDF Reader and Editor on Windows