CVE-2025-55314
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55314 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS, triggered when pages are deleted via JavaScript. The application fails to properly update internal states after page deletion, causing subsequent annotation management operations to dereference invalid or released memory. Affected versions include Foxit PDF Editor prior to 13.2 (including versions up to 13.1.7.23637), 2024 series up to 2024.4.1.27687, 2023 series from 2023.1.0.15510 to 2023.3.0.23028, and 2025.1.0.27937; Foxit PDF Reader up to 2025.1.0.27937 is also affected. The vulnerability was published on December 11, 2025, and carries a CVSS v3.1 base score of 7.8 (High) (Foxit Security Bulletins, Red Hat CVE).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference), arising from improper state management when JavaScript-driven page deletion occurs within a PDF document. When pages are removed via JavaScript, the application does not correctly update internal data structures; subsequent annotation management operations then operate on stale or freed memory references, leading to use-after-free or null pointer dereference conditions. Exploitation requires local access and user interaction — specifically, a victim must open and interact with a maliciously crafted PDF file containing JavaScript that triggers page deletion followed by annotation operations. No public proof-of-concept code has been identified (Foxit Security Bulletins, Red Hat CVE).

Impact

Successful exploitation can result in memory corruption, application crashes (denial of service), and potentially arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. All three security pillars are at risk: confidentiality, integrity, and availability are each rated High under the CVSS scoring. Because the vulnerability executes in the user's context, an attacker could leverage it to access sensitive documents, install malware, or pivot further within the victim's environment (Foxit Security Bulletins, Red Hat CVE).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing embedded JavaScript that deletes one or more pages (e.g., using this.deletePages()) and then immediately performs annotation management operations (e.g., this.getAnnots() or annot.destroy()) on the now-invalid page references.
  2. Deliver the PDF to the target: Distribute the crafted PDF via phishing email, malicious download link, or other social engineering means to a victim running a vulnerable version of Foxit PDF Reader or Editor (prior to 13.2 or 2025.2).
  3. Trigger user interaction: Convince the victim to open the PDF file in Foxit PDF Reader or Editor, which automatically executes the embedded JavaScript.
  4. Trigger memory corruption: The JavaScript executes page deletion, causing internal state to become invalid; subsequent annotation operations dereference the freed/invalid memory, resulting in a crash or, under controlled conditions, arbitrary code execution in the user's context.
  5. Achieve code execution: If the memory corruption is exploitable (e.g., via heap spray or other memory manipulation techniques), the attacker can redirect execution flow to attacker-controlled shellcode or a payload, enabling further system compromise (Foxit Security Bulletins).

Indicators of compromise

  • File System: Unexpected or newly created PDF files in download directories, temp folders, or email attachment staging areas containing embedded JavaScript with deletePages calls.
  • Process: Foxit PDF Reader or Editor process (FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or spawning unusual child processes (e.g., cmd.exe, powershell.exe, curl).
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing Foxit executables with access violation or null pointer exception fault codes.
  • Network: Outbound network connections from Foxit processes to unknown or suspicious external IP addresses or domains shortly after opening a PDF file.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: Foxit PDF Editor 13.2 and Foxit PDF Editor/Reader 2025.2 for both Windows and macOS. Users should update immediately via the Foxit website or in-product update mechanism. As interim mitigations, restrict opening PDF files from untrusted or unknown sources, disable JavaScript execution in Foxit PDF settings if not required, and apply least-privilege principles for accounts used to open PDF documents (Foxit Security Bulletins).

Community reactions

The vulnerability received standard coverage from vulnerability tracking platforms including Tenable, Patch My PC, and VulnDB following its December 2025 disclosure. No notable researcher commentary, vendor statements beyond the security bulletin, or significant social media discussion has been identified beyond routine CVE tracking activity (Foxit Security Bulletins).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management