Use-After-Free Vulnerability in Foxit PDF Reader Across Multiple Versions
CVE-2025-66494

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
19 December 2025

What is CVE-2025-66494?

A use-after-free vulnerability in the PDF file parsing of Foxit PDF Reader allows for the potential execution of arbitrary code due to improper management of PDF objects. Multiple parent objects referencing a single PDF object can be freed unexpectedly while still being in use, creating an opportunity for remote attackers to exploit this flaw. Users are advised to upgrade to the latest versions to mitigate potential risks.

Affected Version(s)

Foxit PDF Editor Windows Versions 2025.2.1 and earlier

Foxit PDF Editor Windows Versions 14.0.1 and earlier

Foxit PDF Editor Windows Versions 13.2.1 and eariler

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous working with Trend Micro Zero Day Initiative
.
CVE-2025-66494 : Use-After-Free Vulnerability in Foxit PDF Reader Across Multiple Versions