Wiz Agents & Workflows are here

CVE-2025-32451
Foxit PDF Reader vulnerability analysis and mitigation

Overview

A memory corruption vulnerability (CVE-2025-32451) was discovered in Foxit Reader 2025.1.0.27937, disclosed on August 13, 2025. The vulnerability stems from the use of an uninitialized pointer in the way Foxit Reader handles signature objects. The vulnerability affects Foxit Reader version 2025.1.0.27937, one of the most popular PDF document readers that aims for feature parity with Adobe's Acrobat Reader (Talos).

Technical details

The vulnerability is caused by an uninitialized pointer in the CPDF_Signature object handling. When a specific JavaScript code related to signature handling is executed, a field in the object is not properly initialized before being accessed. The vulnerability has been assigned a CVSSv3 score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The issue is classified as CWE-824 (Access of Uninitialized Pointer) (Talos).

Impact

The vulnerability can lead to memory corruption and potentially result in arbitrary code execution. The impact is significant as it affects the core functionality of the PDF reader and could allow attackers to execute malicious code with the same privileges as the application (Talos).

Mitigation and workarounds

The vulnerability was patched by the vendor on August 13, 2025. Users are advised to update to the latest version of Foxit Reader. As a workaround, users can disable JavaScript execution in PDF documents and avoid using the browser plugin extension (Talos).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66499HIGH7.8
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesDec 19, 2025
CVE-2025-66498HIGH7.8
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesDec 19, 2025
CVE-2025-66497HIGH7.8
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesDec 19, 2025
CVE-2025-66496HIGH7.8
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesDec 19, 2025
CVE-2025-66495HIGH7.8
  • Foxit PDF ReaderFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesDec 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management