Heap-Based Buffer Overflow in Foxit PDF Reader
CVE-2025-66499
7.8HIGH
What is CVE-2025-66499?
A heap-based buffer overflow vulnerability in Foxit PDF Reader can be exploited when handling specially crafted JBIG2 data. An integer overflow during image buffer size calculations may allow attackers to execute arbitrary code remotely, posing a significant security risk to users of the software.
Affected Version(s)
Foxit PDF Editor Windows Versions 2025.2.1 and earlier
Foxit PDF Editor Windows Versions 14.0.1 and earlier
Foxit PDF Editor Windows Versions 13.2.1 and eariler
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anonymous working with Trend Micro Zero Day Initiative
