CVE-2025-64086
PDF-XChange Editor vulnerability analysis and mitigation

Overview

CVE-2025-64086 is a NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 that allows attackers to cause a Denial of Service (DoS) via crafted input. The vulnerability was published on December 9, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Jeroscope Advisory). Only version 10.7.3.401 of PDF-XChange Editor is confirmed affected.

Technical details

The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the util.readFileIntoStream component of PDF-XChange Editor. An attacker can supply a specially crafted input file or stream that causes the application to dereference a NULL pointer, resulting in an application crash. No authentication or user interaction is required for exploitation, and the attack can be delivered over the network (Jeroscope Advisory, Red Hat CVE).

Impact

Successful exploitation results in a Denial of Service (DoS) condition, crashing the PDF-XChange Editor application. There is no impact on confidentiality or integrity — only availability is affected. Users or automated workflows relying on PDF-XChange Editor for document processing could experience service disruption if targeted with malicious input files (Jeroscope Advisory).

Exploitability

A public advisory with exploitation details is available from Jeroscope (published December 10, 2025), indicating that proof-of-concept or technical details are publicly accessible (Jeroscope Advisory). The EPSS score is approximately 0.018%, reflecting a low probability of widespread exploitation in the near term. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified at this time.

Exploitation steps

  1. Craft malicious input: Prepare a specially crafted PDF or input file designed to trigger a NULL pointer dereference in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401.
  2. Deliver the payload: Deliver the crafted file to a target system running the vulnerable version — this could be via email attachment, file share, web download, or any mechanism that causes the application to open or process the file.
  3. Trigger the vulnerability: When PDF-XChange Editor attempts to read the crafted file using the util.readFileIntoStream function, it dereferences a NULL pointer.
  4. Achieve DoS: The application crashes, causing a Denial of Service for the affected user or automated processing pipeline (Jeroscope Advisory).

Indicators of compromise

  • File System: Presence of unexpected or suspicious PDF/document files delivered via email or download that cause PDF-XChange Editor to crash upon opening.
  • Logs: Application crash logs or Windows Event Viewer entries (Event ID 1000/1001) referencing PDFXEdit.exe or related PDF-XChange Editor processes with access violation or null pointer exception details.
  • Process: Unexpected termination of the PDF-XChange Editor process (PDFXEdit.exe) shortly after opening a document, particularly with faulting module references to the file-reading component.

Mitigation and workarounds

Users should update PDF-XChange Editor to a version beyond 10.7.3.401 that addresses this vulnerability; check the PDF-XChange website for the latest patched release. As a workaround, avoid opening PDF or document files from untrusted sources with the affected version. Organizations using automated document processing pipelines with PDF-XChange Editor should validate input files before processing or temporarily disable processing of externally sourced files until a patch is applied (Jeroscope Advisory, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related PDF-XChange Editor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64086HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2025-64085HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2026-2040HIGH7.3
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoFeb 20, 2026
CVE-2025-58113MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 02, 2025
CVE-2025-47152MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoAug 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management