
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55314 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS, triggered when pages are deleted via JavaScript. The application fails to properly update internal states after page deletion, causing subsequent annotation management operations to dereference invalid or released memory. Affected versions include Foxit PDF Editor prior to 13.2 (including versions up to 13.1.7.23637), 2024 series up to 2024.4.1.27687, 2023 series from 2023.1.0.15510 to 2023.3.0.23028, and 2025.1.0.27937; Foxit PDF Reader up to 2025.1.0.27937 is also affected. The vulnerability was published on December 11, 2025, and carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).
The root cause is classified as CWE-476 (NULL Pointer Dereference), arising from improper state management when JavaScript-driven page deletion occurs within a PDF document. When pages are removed via JavaScript, the application does not correctly update internal data structures; subsequent annotation management operations then operate on stale or freed memory references, leading to use-after-free or null pointer dereference conditions. Exploitation requires local access and user interaction — specifically, a victim must open and interact with a maliciously crafted PDF file containing JavaScript that triggers page deletion followed by annotation operations. No public proof-of-concept code has been identified (Foxit Security Bulletins, Red Hat CVE).
Successful exploitation can result in memory corruption, application crashes (denial of service), and potentially arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. All three security pillars are at risk: confidentiality, integrity, and availability are each rated High under the CVSS scoring. Because the vulnerability executes in the user's context, an attacker could leverage it to access sensitive documents, install malware, or pivot further within the victim's environment (Foxit Security Bulletins, Red Hat CVE).
this.deletePages()) and then immediately performs annotation management operations (e.g., this.getAnnots() or annot.destroy()) on the now-invalid page references.deletePages calls.FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or spawning unusual child processes (e.g., cmd.exe, powershell.exe, curl).Foxit has released patched versions addressing this vulnerability: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2 for both Windows and macOS. Users should update immediately via the Foxit website or in-product update mechanism. As interim mitigations, restrict opening PDF files from untrusted or unknown sources, disable JavaScript execution in Foxit PDF settings if not required, and apply least-privilege principles for accounts used to open PDF documents (Foxit Security Bulletins).
The vulnerability received standard coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB following its December 2025 disclosure. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified beyond routine CVE tracking activity (Foxit Security Bulletins).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."