CVE-2025-55310
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55310 is a local file integrity vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS that allows an attacker who can alter or replace static HTML files used by the StartPage feature to cause the application to load malicious content upon startup. It affects Foxit PDF Editor versions before 13.2 and 2025 before 2025.2, as well as Foxit PDF Reader versions up to and including 2025.1.0.27937 (Windows) and 2025.1.0.66692 (macOS). The vulnerability was published on December 11, 2025, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.3 (High) (Foxit Security Bulletins, Red Hat CVE).

Technical details

The root cause is classified as CWE-494 (Download of Code Without Integrity Check), meaning the application loads StartPage HTML files without verifying their integrity or authenticity. An attacker with local access who can write to or replace the static HTML files used by the StartPage feature can inject malicious HTML/JavaScript content that executes within the application's context at startup. Exploitation requires low privileges and user interaction (launching the application), and the attack vector is local. No public proof-of-concept code has been identified (Foxit Security Bulletins, Red Hat CVE).

Impact

Successful exploitation can result in information disclosure, unauthorized data access, and potential execution of malicious content within the Foxit application context at startup. Because the vulnerability operates within the scope of the application (scope unchanged), the primary risks are confined to the affected host, including exposure of sensitive documents or credentials accessible to the Foxit process. The CVSS metrics indicate high confidentiality, integrity, and availability impact, suggesting a fully compromised application session is possible if exploited (Foxit Security Bulletins, Red Hat CVE).

Exploitation steps

  1. Gain local access: Obtain low-privileged local access to a system running a vulnerable version of Foxit PDF Reader or PDF Editor (before version 13.2 or 2025.2).
  2. Locate StartPage HTML files: Identify the directory containing the static HTML files used by the Foxit StartPage feature (typically within the application's installation or user data directory).
  3. Replace or modify HTML files: Alter or replace the target HTML files with malicious content containing injected JavaScript or HTML that performs the desired action (e.g., credential harvesting, data exfiltration, or loading a remote resource).
  4. Trigger application startup: Wait for or induce the victim user to launch Foxit PDF Reader or PDF Editor, causing the application to load the tampered StartPage HTML without integrity verification.
  5. Achieve objective: The malicious content executes within the application context, potentially disclosing sensitive information, accessing user data, or performing further actions depending on the injected payload (Foxit Security Bulletins).

Indicators of compromise

  • File System: Unexpected modifications to static HTML files in the Foxit PDF Reader/Editor installation directory or user profile data directory (e.g., StartPage HTML files with altered timestamps or content); presence of unfamiliar JavaScript or iframe tags within Foxit StartPage HTML files.
  • Logs: Application event logs showing Foxit loading content from unexpected local paths or external URLs at startup; OS audit logs recording write access to Foxit HTML resource files by non-Foxit processes or unexpected user accounts.
  • Process: Foxit PDF process spawning unexpected child processes or making unusual outbound network connections shortly after application launch.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: update Foxit PDF Editor to version 13.2 or later, and Foxit PDF Reader/Editor 2025 series to version 2025.2 or later. As interim workarounds, administrators should restrict write permissions on the Foxit application and user data directories to prevent unauthorized modification of StartPage HTML files, implement file integrity monitoring on those directories, and apply application whitelisting to block unauthorized file modifications. Users should avoid running Foxit applications under accounts with unnecessary local write privileges (Foxit Security Bulletins).

Community reactions

The vulnerability received routine coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB shortly after disclosure. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified in connection with this CVE.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management