Out-Of-Bounds Read Information Disclosure Vulnerability in PDF-XChange Editor by Tracker Software
CVE-2025-6657

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6657?

The vulnerability present in PDF-XChange Editor involves improper validation of user-supplied data during the parsing of PRC files. This flaw can lead to the disclosure of sensitive information if exploited by remote attackers. User interaction is necessary, as victims must either visit a malicious webpage or open a malicious file. By leveraging this vulnerability alongside others, an attacker could potentially execute arbitrary code within the current process.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6657 : Out-Of-Bounds Read Information Disclosure Vulnerability in PDF-XChange Editor by Tracker Software