Memory Corruption Vulnerability in Foxit PDF Reader
CVE-2025-66498

5.3MEDIUM

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
19 December 2025

What is CVE-2025-66498?

A memory corruption vulnerability is present in Foxit PDF Reader, stemming from inadequate bounds checking while processing 3D annotations. Specifically, when users open a PDF file that contains malformed or specially crafted PRC content, this could lead to out-of-bounds memory access, potentially resulting in memory corruption. Users are advised to update to the latest version to mitigate any risk associated with this vulnerability.

Affected Version(s)

Foxit PDF Editor Windows Versions 2025.2.1 and earlier

Foxit PDF Editor Windows Versions 14.0.1 and earlier

Foxit PDF Editor Windows Versions 13.2.1 and eariler

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mat Powell of Trend of Trend Micro Zero Day Initiative
.
CVE-2025-66498 : Memory Corruption Vulnerability in Foxit PDF Reader