CVE-2025-64085
PDF-XChange Editor vulnerability analysis and mitigation

Overview

CVE-2025-64085 is a NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor version 10.7.3.401 that allows attackers to cause a Denial of Service (DoS) via crafted input. It was published on December 9, 2025, and classified under CWE-476 (NULL Pointer Dereference). The vulnerability carries a CVSS v3.1 base score of 7.5 (High), with network-based attack vector and no authentication required (Red Hat CVE, Jeroscope Advisory).

Technical details

The root cause is a NULL pointer dereference (CWE-476) within the importDataObject() function of PDF-XChange Editor v10.7.3.401. An attacker can trigger this flaw by supplying a specially crafted PDF or data object input that causes the function to dereference a NULL pointer, resulting in an application crash. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit remotely. A proof-of-concept advisory detailing the vulnerability mechanics is publicly available (Jeroscope Advisory).

Impact

Successful exploitation crashes the PDF-XChange Editor application, resulting in a complete loss of availability for the affected process. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability alone. In environments where PDF-XChange Editor is used for critical document workflows, repeated exploitation could significantly disrupt user productivity and business operations (Red Hat CVE, Jeroscope Advisory).

Exploitability

A proof-of-concept exploit is publicly available via the Jeroscope security advisory published December 10, 2025. As of the time of reporting, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, indicating a low probability of exploitation in the near term (Jeroscope Advisory, Red Hat CVE).

Exploitation steps

  1. Craft a malicious PDF: Create a specially crafted PDF file or data object designed to trigger a NULL pointer dereference when processed by the importDataObject() function in PDF-XChange Editor v10.7.3.401.
  2. Deliver the payload: Distribute the malicious file to a target user via email attachment, web download, or shared network location — no authentication to the application is required.
  3. Trigger processing: Induce the target to open the crafted file in PDF-XChange Editor, causing the application to invoke the vulnerable importDataObject() function.
  4. Achieve DoS: The NULL pointer dereference causes the application to crash, resulting in a denial of service for the affected user or process (Jeroscope Advisory).

Indicators of compromise

  • File System: Presence of unexpected or suspicious PDF files received from external sources, particularly those with unusual structure or metadata.
  • Logs: Application crash logs or Windows Event Viewer entries showing PDF-XChange Editor (PDFXEdit.exe) terminating unexpectedly with an access violation or null pointer exception.
  • Process: Repeated or automated crashes of the PDFXEdit.exe process, especially when opening specific PDF files; crash dump files (.dmp) generated in the application or system temp directory.

Mitigation and workarounds

The patch status for CVE-2025-64085 is not explicitly confirmed in available sources; users should check the PDF-XChange website for the latest updates and apply any available patches immediately. As interim mitigations: avoid opening PDF files from untrusted or unknown sources in PDF-XChange Editor; implement application whitelisting to restrict which files can be processed; and consider restricting access to the application in high-risk environments. Monitoring the vendor's security update channel for a patched release is strongly recommended (Red Hat CVE, Jeroscope Advisory).

Additional resources


SourceThis report was generated using AI

Related PDF-XChange Editor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64086HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2025-64085HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2026-2040HIGH7.3
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoFeb 20, 2026
CVE-2025-58113MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 02, 2025
CVE-2025-47152MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoAug 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management