
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55310 is a local file integrity vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS that allows an attacker who can alter or replace static HTML files used by the StartPage feature to cause the application to load malicious content upon startup. It affects Foxit PDF Editor versions before 13.2 and 2025 before 2025.2, as well as Foxit PDF Reader versions up to and including 2025.1.0.27937 (Windows) and 2025.1.0.66692 (macOS). The vulnerability was published on December 11, 2025, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.3 (High) (Foxit Security Bulletins, Red Hat CVE).
The root cause is classified as CWE-494 (Download of Code Without Integrity Check), meaning the application loads StartPage HTML files without verifying their integrity or authenticity. An attacker with local access who can write to or replace the static HTML files used by the StartPage feature can inject malicious HTML/JavaScript content that executes within the application's context at startup. Exploitation requires low privileges and user interaction (launching the application), and the attack vector is local. No public proof-of-concept code has been identified (Foxit Security Bulletins, Red Hat CVE).
Successful exploitation can result in information disclosure, unauthorized data access, and potential execution of malicious content within the Foxit application context at startup. Because the vulnerability operates within the scope of the application (scope unchanged), the primary risks are confined to the affected host, including exposure of sensitive documents or credentials accessible to the Foxit process. The CVSS metrics indicate high confidentiality, integrity, and availability impact, suggesting a fully compromised application session is possible if exploited (Foxit Security Bulletins, Red Hat CVE).
Foxit has released patched versions addressing this vulnerability: update Foxit PDF Editor to version 13.2 or later, and Foxit PDF Reader/Editor 2025 series to version 2025.2 or later. As interim workarounds, administrators should restrict write permissions on the Foxit application and user data directories to prevent unauthorized modification of StartPage HTML files, implement file integrity monitoring on those directories, and apply application whitelisting to block unauthorized file modifications. Users should avoid running Foxit applications under accounts with unnecessary local write privileges (Foxit Security Bulletins).
The vulnerability received routine coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB shortly after disclosure. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified in connection with this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."