Information Disclosure Vulnerability in Foxit PDF Reader
CVE-2025-9325

3.3LOW

Key Information:

Vendor

Foxit

Vendor
CVE Published:
2 September 2025

What is CVE-2025-9325?

The vulnerability arises from the improper validation of user-supplied data during the parsing of PRC files in Foxit PDF Reader, which triggers an out-of-bounds read. By enticing users to open specially crafted PRC files or visit malicious pages, attackers can exploit this flaw to reveal sensitive information. This vulnerability can potentially be combined with other existing vulnerabilities to execute arbitrary code in the process context, posing significant security risks for users.

Affected Version(s)

PDF Reader 2024.4.0.27683

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9325 : Information Disclosure Vulnerability in Foxit PDF Reader