CVE-2025-55313
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55313 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS that allows potential arbitrary code execution when processing crafted PDF files. The flaw was published on December 11, 2025, and affects Foxit PDF Editor versions up to 13.1.7.63027, 2023.x up to 2023.3.0.23028, 2024.x up to 2024.4.1.27687, and 2025.x up to 2025.1.0.27937, as well as Foxit PDF Reader up to 2025.1.0.27937. Fixed versions are Foxit PDF Editor 13.2 and 2025.2. It carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient handling of memory allocation failures triggered by assigning an extremely large value to a form field's charLimit property via embedded JavaScript in a PDF document. When the allocation fails, the application does not properly handle the error condition, leading to memory corruption. Exploitation requires local delivery of a malicious PDF file and user interaction (opening the file), with no privileges required on the part of the attacker (Foxit Security Bulletins, Red Hat CVE).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the user running Foxit PDF Reader or Editor, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, enabling unauthorized data access, malware installation, or use of the compromised host as a pivot point for further attacks. Both Windows and macOS platforms are affected (Foxit Security Bulletins, Red Hat CVE).

Exploitation steps

  1. Craft malicious PDF: Create a PDF document containing embedded JavaScript that sets a form field's charLimit property to an extremely large integer value (e.g., this.getField('field1').charLimit = 0xFFFFFFFF;), designed to trigger a memory allocation failure in vulnerable Foxit versions.
  2. Deliver the payload: Distribute the malicious PDF via phishing email, malicious download link, or other social engineering vector to a target user running a vulnerable version of Foxit PDF Reader or Editor.
  3. User opens the file: The target user opens the crafted PDF in Foxit PDF Reader or Editor, triggering JavaScript execution and the vulnerable charLimit assignment.
  4. Memory corruption triggered: The application attempts to allocate memory for the oversized charLimit value; upon allocation failure, insufficient error handling results in memory corruption (e.g., use-after-free or heap corruption).
  5. Arbitrary code execution: The attacker leverages the memory corruption condition to redirect execution flow and run arbitrary code in the context of the victim user, potentially installing malware or establishing persistence (Foxit Security Bulletins).

Indicators of compromise

  • Process: Unexpected child processes spawned by Foxit PDF Reader or Editor (e.g., cmd.exe, powershell.exe, bash, curl, wget) following the opening of a PDF file.
  • File System: Newly created or modified files in user temp directories (%TEMP%, /tmp) or startup folders shortly after opening a PDF; unexpected executables or scripts dropped by the Foxit process.
  • Network: Outbound network connections initiated by the Foxit PDF process to unknown or suspicious external IP addresses or domains immediately after PDF opening.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing Foxit PDF Reader/Editor with memory access violations; macOS crash reports for FoxitPDFReader or FoxitPDFEditor processes.

Mitigation and workarounds

Foxit has released patched versions: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2 for both Windows and macOS. Users should update immediately via the Foxit download portal or built-in updater. As interim mitigations, administrators can disable JavaScript execution in Foxit PDF Reader/Editor (Preferences → JavaScript → uncheck "Enable JavaScript Actions"), implement PDF file screening before delivery to end users, and educate users about the risks of opening PDFs from untrusted sources (Foxit Security Bulletins).

Community reactions

Patch management services such as Patch My PC included CVE-2025-55313 in their August 2025 catalog release, indicating routine tracking by enterprise patch management tooling. Tenable also flagged the vulnerability in their plugin pipeline. No significant independent researcher commentary or broad media coverage has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management