
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55308 is a use-after-free vulnerability in Foxit PDF Reader and PDF Editor for Windows that can be triggered by a crafted PDF containing JavaScript invoking closeDoc() while internal objects are still in use, causing premature object release and potential memory corruption. Affected versions include Foxit PDF Editor up to and including 13.1.7.23637 (fixed in 13.2), PDF Editor 2024.x up to 2024.4.1.27687, PDF Editor 2023.x from 2023.1.0.15510 to 2023.3.0.23028, PDF Editor 2025.1.0.27937, and PDF Reader up to and including 2025.1.0.27937 (fixed in 2025.2). The vulnerability was published on December 11, 2025, with a CVSS v3.1 base score of 6.7 (Medium) (Foxit Security Bulletins, Red Hat CVE).
The root cause is a use-after-free condition (CWE-416) in Foxit's JavaScript engine for PDF processing. When a crafted PDF executes JavaScript that calls closeDoc() while internal document objects are still referenced and in use, those objects are prematurely freed from memory. Subsequent access to these freed memory regions can result in memory corruption. Exploitation requires a user to open a malicious PDF file (user interaction required) and operates in a local attack vector with low privileges and high attack complexity (Foxit Security Bulletins, Red Hat CVE).
Successful exploitation can lead to memory corruption with high confidentiality, integrity, and availability impacts. The primary risk is information disclosure through reading freed memory contents, but memory corruption could also enable arbitrary code execution in more advanced exploitation scenarios. Because exploitation requires the victim to open a specially crafted PDF, the attack surface is limited to users who interact with untrusted PDF documents (Foxit Security Bulletins).
closeDoc() at a point where internal document objects (e.g., annotation or form field objects) are still actively referenced by the Foxit engine.closeDoc() call causes premature deallocation of in-use internal objects.FoxitPDFReader.exe or FoxitPDFEditor.exe with access violation or heap corruption errors.Foxit has released patched versions addressing this vulnerability: update Foxit PDF Editor to version 13.2 or later, or to version 2025.2 or later for the 2025 product line; update Foxit PDF Reader to the latest available version (2025.2+). As an interim workaround, users should avoid opening PDF files from untrusted or unknown sources, and consider disabling JavaScript execution within the PDF reader settings if the application supports it. Patch details and downloads are available via the Foxit security bulletins page (Foxit Security Bulletins).
Tenable published detection plugins for this vulnerability shortly after disclosure, and patch management services such as Patch My PC included it in their August 2025 catalog update (Foxit Security Bulletins). No significant independent researcher commentary or broad media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."