Remote Code Execution Vulnerability in Foxit PDF Reader PRC File Parsing
CVE-2025-9326

7.8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
2 September 2025

What is CVE-2025-9326?

A vulnerability exists in the Foxit PDF Reader due to improper validation of PRC file data, which could lead to an out-of-bounds read. Exploitation requires user interaction, as it necessitates the opening of a malicious file or visiting a compromised web page. Successfully exploiting this flaw allows attackers to execute arbitrary code within the context of the affected application, potentially compromising user data and system integrity.

Affected Version(s)

PDF Reader 2024.4.0.27683

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9326 : Remote Code Execution Vulnerability in Foxit PDF Reader PRC File Parsing