
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55313 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS that allows potential arbitrary code execution when processing crafted PDF files. The flaw was published on December 11, 2025, and affects Foxit PDF Editor versions up to 13.1.7.63027, 2023.x up to 2023.3.0.23028, 2024.x up to 2024.4.1.27687, and 2025.x up to 2025.1.0.27937, as well as Foxit PDF Reader up to 2025.1.0.27937. Fixed versions are Foxit PDF Editor 13.2 and 2025.2. It carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient handling of memory allocation failures triggered by assigning an extremely large value to a form field's charLimit property via embedded JavaScript in a PDF document. When the allocation fails, the application does not properly handle the error condition, leading to memory corruption. Exploitation requires local delivery of a malicious PDF file and user interaction (opening the file), with no privileges required on the part of the attacker (Foxit Security Bulletins, Red Hat CVE).
Successful exploitation allows an attacker to execute arbitrary code in the context of the user running Foxit PDF Reader or Editor, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, enabling unauthorized data access, malware installation, or use of the compromised host as a pivot point for further attacks. Both Windows and macOS platforms are affected (Foxit Security Bulletins, Red Hat CVE).
charLimit property to an extremely large integer value (e.g., this.getField('field1').charLimit = 0xFFFFFFFF;), designed to trigger a memory allocation failure in vulnerable Foxit versions.charLimit assignment.charLimit value; upon allocation failure, insufficient error handling results in memory corruption (e.g., use-after-free or heap corruption).cmd.exe, powershell.exe, bash, curl, wget) following the opening of a PDF file.%TEMP%, /tmp) or startup folders shortly after opening a PDF; unexpected executables or scripts dropped by the Foxit process.FoxitPDFReader or FoxitPDFEditor processes.Foxit has released patched versions: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2 for both Windows and macOS. Users should update immediately via the Foxit download portal or built-in updater. As interim mitigations, administrators can disable JavaScript execution in Foxit PDF Reader/Editor (Preferences → JavaScript → uncheck "Enable JavaScript Actions"), implement PDF file screening before delivery to end users, and educate users about the risks of opening PDFs from untrusted sources (Foxit Security Bulletins).
Patch management services such as Patch My PC included CVE-2025-55313 in their August 2025 catalog release, indicating routine tracking by enterprise patch management tooling. Tenable also flagged the vulnerability in their plugin pipeline. No significant independent researcher commentary or broad media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."