CVE-2025-55312
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55312 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows, triggered when pages are deleted via JavaScript, causing the application to dereference invalid or released memory during subsequent annotation management operations. It affects Foxit PDF Editor versions before 13.2 (including versions up to 13.1.7.63027) and 2025 series versions before 2025.2 (including 2025.1.0.66692 and 2025.1.0.27937), as well as Foxit PDF Reader versions up to 2025.1.0.66692 and 2025.1.0.27937. The vulnerability was published on December 11, 2025, with a patch available as of December 18, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference), arising from the application's failure to properly update internal state when PDF pages are deleted through JavaScript execution. After page deletion, subsequent annotation management operations operate under the assumption that internal state pointers remain valid; however, those pointers may reference invalid or already-freed memory regions, leading to a use-after-free or null dereference condition. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PDF file containing malicious JavaScript that triggers the page deletion sequence. No public proof-of-concept code has been identified at this time (Foxit Security Bulletins, Red Hat CVE).

Impact

Successful exploitation can result in memory corruption, application crashes (denial of service), and potentially arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. Given the high confidentiality, integrity, and availability impact ratings, a successful attack could allow an attacker to read sensitive data, modify files, or fully compromise the affected system. The attack is constrained to local scope with required user interaction, limiting mass exploitation but making it a viable vector for targeted attacks via malicious PDF documents (Foxit Security Bulletins).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing embedded JavaScript that programmatically deletes one or more pages (e.g., using this.deletePages() or equivalent Foxit-supported JavaScript API calls).
  2. Embed annotation operations: After the page deletion JavaScript, include additional annotation management operations (e.g., adding, modifying, or accessing annotations) that will execute against the now-invalid internal state.
  3. Deliver the PDF to the target: Use social engineering, phishing email, or a malicious download link to deliver the crafted PDF to a victim running a vulnerable version of Foxit PDF Reader or Editor (before 13.2 or before 2025.2).
  4. Trigger execution: The victim opens the PDF; Foxit executes the embedded JavaScript, deletes the pages, and then processes the annotation operations — dereferencing invalid or freed memory.
  5. Achieve code execution or crash: Depending on memory layout and heap state, the memory corruption may result in an application crash (DoS) or, with additional exploitation techniques (e.g., heap grooming), arbitrary code execution in the user's security context (Foxit Security Bulletins).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited PDF files received via email or downloads; PDF files containing embedded JavaScript with deletePages or similar page manipulation calls combined with annotation API usage.
  • Process: Foxit PDF Reader or Editor process (FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or spawning unusual child processes after opening a PDF document.
  • Logs: Windows Event Log entries (Application log) showing application crash events (Event ID 1000) attributed to Foxit PDF processes; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or Foxit's own crash reporting directory.
  • Network: Unexpected outbound network connections from Foxit processes to unknown external IP addresses following PDF document opening, which may indicate post-exploitation activity.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2. Users should update immediately to these versions via the Foxit website or built-in update mechanism. As interim mitigations, organizations should implement strict PDF file vetting before opening documents from untrusted sources, limit user privileges for PDF interactions, use application whitelisting, and monitor for unusual Foxit application behavior. Disabling JavaScript execution in Foxit PDF Reader/Editor settings (Preferences → JavaScript → uncheck "Enable JavaScript Actions") can also reduce the attack surface (Foxit Security Bulletins).

Community reactions

The vulnerability received standard coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB shortly after disclosure. Patch My PC included the fix in their August 2025 third-party software update catalog, indicating uptake in enterprise patch management workflows. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified for this CVE (Foxit Security Bulletins).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management