CVE-2025-55307
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55307 is an out-of-bounds read vulnerability in Foxit PDF Reader and PDF Editor for Windows. It is triggered when a user opens a malicious PDF containing a crafted JavaScript call to search.query() with a specially crafted cDIPath parameter (e.g., "/"), causing an out-of-bounds read in the application's internal path-parsing logic. Affected versions include Foxit PDF Editor up to 13.1.7.23637, versions 2023.1.0.15510–2023.3.0.23028, 2024.1.0.23997–2024.4.1.27687, and 2025.1.0.27937, as well as Foxit PDF Reader up to 2025.1.0.27937. The vulnerability was published on December 11, 2025, and carries a CVSS v3.1 base score of 3.3 (Low) (Red Hat CVE, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), triggered within the internal path-parsing logic of Foxit PDF Reader/Editor when processing the cDIPath parameter passed to the JavaScript search.query() function. An attacker crafts a PDF that, upon opening, executes embedded JavaScript invoking search.query() with a malformed path value (e.g., "/"), causing the application to read memory beyond the intended buffer boundary. The attack vector is local (the user must open the malicious file), requires no privileges, but does require user interaction. No public proof-of-concept code has been identified (Red Hat CVE, Foxit Security Bulletins).

Impact

Successful exploitation may result in information disclosure by exposing memory contents beyond intended boundaries, or memory corruption that could lead to application crashes. The confidentiality impact is rated low, with no integrity or availability impact assessed under the current CVSS scoring. While the vulnerability requires user interaction and is limited in scope, memory corruption outcomes could theoretically be leveraged for more severe consequences in chained attack scenarios (Red Hat CVE).

Exploitation steps

  1. Craft malicious PDF: Create a PDF document containing embedded JavaScript that calls search.query() with a crafted cDIPath parameter value such as "/" designed to trigger the out-of-bounds read in Foxit's path-parsing logic.
  2. Deliver the PDF: Distribute the malicious PDF to a target user via phishing email, malicious download link, or other social engineering method.
  3. Trigger execution: The victim opens the PDF in a vulnerable version of Foxit PDF Reader or Editor for Windows (prior to 13.2 or 2025.2), causing the embedded JavaScript to execute automatically or upon user interaction with the document.
  4. Out-of-bounds read occurs: The search.query() call with the malformed cDIPath parameter causes the application to read memory beyond the intended buffer, potentially exposing sensitive memory contents or causing memory corruption.
  5. Achieve objective: Depending on what memory is read, an attacker may obtain sensitive information from the process memory, or the memory corruption may cause an application crash (Foxit Security Bulletins).

Indicators of compromise

  • File System: Presence of unexpected or suspicious PDF files received via email or downloaded from untrusted sources; PDFs containing embedded JavaScript targeting search.query() with unusual cDIPath values.
  • Process: Foxit PDF Reader or Editor process (FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or generating application error logs after opening a PDF file.
  • Logs: Windows Event Logs showing application crashes or faulting module entries related to Foxit PDF processes; JavaScript execution logs within Foxit if logging is enabled.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: update Foxit PDF Editor to version 13.2 or later, or to version 2025.2 or later for the 2025 product line. Foxit PDF Reader users should update to the latest patched version as indicated in Foxit's official security bulletins. As interim mitigations, administrators should consider disabling JavaScript execution in Foxit PDF applications via application settings or group policy, and users should be advised to avoid opening PDF files from untrusted or unknown sources (Foxit Security Bulletins).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management