Information Disclosure Vulnerability in PDF-XChange Editor
CVE-2025-6656

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6656?

The PDF-XChange Editor is affected by a vulnerability that arises from improper validation of user-supplied data during the parsing of PRC files. This flaw can lead to an out-of-bounds read, potentially disclosing sensitive information. In this scenario, user interaction is necessary, as the victim must open a malicious PRC file or visit a compromised web page to trigger the vulnerability. Attackers could leverage this issue to read past the end of an allocated object, and it may be exploited in conjunction with other vulnerabilities to execute arbitrary code within the current process context.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6656 : Information Disclosure Vulnerability in PDF-XChange Editor