Information Disclosure Vulnerability in PDF-XChange Editor Software
CVE-2025-6655

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6655?

The vulnerability within PDF-XChange Editor arises from a flaw in the parsing of PRC files, which fails to properly validate user-supplied data. This oversight can lead to an out-of-bounds read, allowing remote attackers to disclose sensitive information. User interaction is required for exploitation, as the victim must either access a malicious web page or open a compromised file. This flaw may also allow an attacker to leverage it in combination with other weaknesses to execute arbitrary code within the current process context.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6655 : Information Disclosure Vulnerability in PDF-XChange Editor Software