CVE-2025-55308
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55308 is a use-after-free vulnerability in Foxit PDF Reader and PDF Editor for Windows that can be triggered by a crafted PDF containing JavaScript invoking closeDoc() while internal objects are still in use, causing premature object release and potential memory corruption. Affected versions include Foxit PDF Editor up to and including 13.1.7.23637 (fixed in 13.2), PDF Editor 2024.x up to 2024.4.1.27687, PDF Editor 2023.x from 2023.1.0.15510 to 2023.3.0.23028, PDF Editor 2025.1.0.27937, and PDF Reader up to and including 2025.1.0.27937 (fixed in 2025.2). The vulnerability was published on December 11, 2025, with a CVSS v3.1 base score of 6.7 (Medium) (Foxit Security Bulletins, Red Hat CVE).

Technical details

The root cause is a use-after-free condition (CWE-416) in Foxit's JavaScript engine for PDF processing. When a crafted PDF executes JavaScript that calls closeDoc() while internal document objects are still referenced and in use, those objects are prematurely freed from memory. Subsequent access to these freed memory regions can result in memory corruption. Exploitation requires a user to open a malicious PDF file (user interaction required) and operates in a local attack vector with low privileges and high attack complexity (Foxit Security Bulletins, Red Hat CVE).

Impact

Successful exploitation can lead to memory corruption with high confidentiality, integrity, and availability impacts. The primary risk is information disclosure through reading freed memory contents, but memory corruption could also enable arbitrary code execution in more advanced exploitation scenarios. Because exploitation requires the victim to open a specially crafted PDF, the attack surface is limited to users who interact with untrusted PDF documents (Foxit Security Bulletins).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing embedded JavaScript that calls closeDoc() at a point where internal document objects (e.g., annotation or form field objects) are still actively referenced by the Foxit engine.
  2. Deliver the PDF to the target: Distribute the crafted PDF via email attachment, web download, or other social engineering means to a user running a vulnerable version of Foxit PDF Reader or Editor for Windows.
  3. Trigger the vulnerability: When the victim opens the PDF, Foxit's JavaScript engine executes the embedded script. The closeDoc() call causes premature deallocation of in-use internal objects.
  4. Exploit the freed memory: With the use-after-free condition triggered, an attacker with a carefully timed or structured payload may read from or write to the freed memory region, potentially leaking sensitive memory contents (information disclosure) or achieving code execution through further memory manipulation (Foxit Security Bulletins).

Indicators of compromise

  • File System: Unexpected or suspicious PDF files received from unknown sources, particularly those containing embedded JavaScript.
  • Process: Foxit PDF Reader or Editor processes exhibiting crashes, unexpected termination, or spawning unusual child processes after opening a PDF.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing FoxitPDFReader.exe or FoxitPDFEditor.exe with access violation or heap corruption errors.
  • Network: Outbound network connections initiated by the Foxit process to unexpected external IP addresses or domains shortly after opening a PDF document.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: update Foxit PDF Editor to version 13.2 or later, or to version 2025.2 or later for the 2025 product line; update Foxit PDF Reader to the latest available version (2025.2+). As an interim workaround, users should avoid opening PDF files from untrusted or unknown sources, and consider disabling JavaScript execution within the PDF reader settings if the application supports it. Patch details and downloads are available via the Foxit security bulletins page (Foxit Security Bulletins).

Community reactions

Tenable published detection plugins for this vulnerability shortly after disclosure, and patch management services such as Patch My PC included it in their August 2025 catalog update (Foxit Security Bulletins). No significant independent researcher commentary or broad media coverage has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management