
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55312 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows, triggered when pages are deleted via JavaScript, causing the application to dereference invalid or released memory during subsequent annotation management operations. It affects Foxit PDF Editor versions before 13.2 (including versions up to 13.1.7.63027) and 2025 series versions before 2025.2 (including 2025.1.0.66692 and 2025.1.0.27937), as well as Foxit PDF Reader versions up to 2025.1.0.66692 and 2025.1.0.27937. The vulnerability was published on December 11, 2025, with a patch available as of December 18, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).
The root cause is classified as CWE-476 (NULL Pointer Dereference), arising from the application's failure to properly update internal state when PDF pages are deleted through JavaScript execution. After page deletion, subsequent annotation management operations operate under the assumption that internal state pointers remain valid; however, those pointers may reference invalid or already-freed memory regions, leading to a use-after-free or null dereference condition. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PDF file containing malicious JavaScript that triggers the page deletion sequence. No public proof-of-concept code has been identified at this time (Foxit Security Bulletins, Red Hat CVE).
Successful exploitation can result in memory corruption, application crashes (denial of service), and potentially arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. Given the high confidentiality, integrity, and availability impact ratings, a successful attack could allow an attacker to read sensitive data, modify files, or fully compromise the affected system. The attack is constrained to local scope with required user interaction, limiting mass exploitation but making it a viable vector for targeted attacks via malicious PDF documents (Foxit Security Bulletins).
this.deletePages() or equivalent Foxit-supported JavaScript API calls).deletePages or similar page manipulation calls combined with annotation API usage.FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or spawning unusual child processes after opening a PDF document..dmp) generated in %LOCALAPPDATA%\CrashDumps or Foxit's own crash reporting directory.Foxit has released patched versions addressing this vulnerability: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2. Users should update immediately to these versions via the Foxit website or built-in update mechanism. As interim mitigations, organizations should implement strict PDF file vetting before opening documents from untrusted sources, limit user privileges for PDF interactions, use application whitelisting, and monitor for unusual Foxit application behavior. Disabling JavaScript execution in Foxit PDF Reader/Editor settings (Preferences → JavaScript → uncheck "Enable JavaScript Actions") can also reduce the attack surface (Foxit Security Bulletins).
The vulnerability received standard coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB shortly after disclosure. Patch My PC included the fix in their August 2025 third-party software update catalog, indicating uptake in enterprise patch management workflows. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified for this CVE (Foxit Security Bulletins).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."