
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55311 is a digital signature bypass vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS. A crafted PDF can leverage JavaScript to alter annotation content and then clear the file's modification status, effectively hiding document changes from digital signature verification. This allows an attacker to present a tampered PDF as unmodified and legitimately signed, undermining document integrity assurances. Affected versions include Foxit PDF Editor/Reader before 13.2 and 2025 before 2025.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Foxit Security Bulletins).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). The vulnerability arises because Foxit's JavaScript engine exposes interfaces that allow a PDF's annotation content to be modified and its modification flag to be reset programmatically, without invalidating the existing digital signature. An attacker crafts a PDF that, upon opening, executes embedded JavaScript to alter annotations and suppress the dirty/modified state of the document, causing the signature validation UI to report the document as unmodified. Exploitation requires user interaction — the victim must open the malicious PDF in a vulnerable version of Foxit PDF Reader or Editor (Red Hat CVE, Foxit Security Bulletins).
Successful exploitation allows an attacker to present a tampered PDF document as if it were unmodified and bearing a valid digital signature, directly compromising document integrity. There is no confidentiality or availability impact; the primary risk is a high-integrity violation that enables document forgery and social engineering attacks. Victims may be deceived into trusting falsified contracts, legal documents, or other signed materials, with no visible indication of tampering (Red Hat CVE).
Foxit has released patched versions addressing this vulnerability: update to Foxit PDF Editor 13.2 or later, or Foxit PDF 2025.2 or later for both Windows and macOS (Foxit Security Bulletins). As interim mitigations, organizations should disable JavaScript execution in Foxit PDF Reader/Editor settings, implement strict PDF validation processes, and train users to be cautious when opening PDFs from untrusted sources. Additional document verification methods (e.g., verifying signatures through an independent tool) are recommended until patching is complete.
The vulnerability was published on December 11, 2025, and has been tracked by patch management services including Tenable and Patch My PC, indicating awareness in the enterprise patch management community (Tenable, Patch My PC). No significant public researcher commentary or major media coverage has been identified beyond standard vulnerability database entries and automated tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."