Heap-Based Buffer Overflow in Foxit PDF Reader
CVE-2025-66499

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
19 December 2025

What is CVE-2025-66499?

A heap-based buffer overflow vulnerability in Foxit PDF Reader can be exploited when handling specially crafted JBIG2 data. An integer overflow during image buffer size calculations may allow attackers to execute arbitrary code remotely, posing a significant security risk to users of the software.

Affected Version(s)

Foxit PDF Editor Windows Versions 2025.2.1 and earlier

Foxit PDF Editor Windows Versions 14.0.1 and earlier

Foxit PDF Editor Windows Versions 13.2.1 and eariler

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous working with Trend Micro Zero Day Initiative
.
CVE-2025-66499 : Heap-Based Buffer Overflow in Foxit PDF Reader