
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64086 is a NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 that allows attackers to cause a Denial of Service (DoS) via crafted input. The vulnerability was published on December 9, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Jeroscope Advisory). Only version 10.7.3.401 of PDF-XChange Editor is confirmed affected.
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the util.readFileIntoStream component of PDF-XChange Editor. An attacker can supply a specially crafted input file or stream that causes the application to dereference a NULL pointer, resulting in an application crash. No authentication or user interaction is required for exploitation, and the attack can be delivered over the network (Jeroscope Advisory, Red Hat CVE).
Successful exploitation results in a Denial of Service (DoS) condition, crashing the PDF-XChange Editor application. There is no impact on confidentiality or integrity — only availability is affected. Users or automated workflows relying on PDF-XChange Editor for document processing could experience service disruption if targeted with malicious input files (Jeroscope Advisory).
A public advisory with exploitation details is available from Jeroscope (published December 10, 2025), indicating that proof-of-concept or technical details are publicly accessible (Jeroscope Advisory). The EPSS score is approximately 0.018%, reflecting a low probability of widespread exploitation in the near term. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified at this time.
util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401.util.readFileIntoStream function, it dereferences a NULL pointer.PDFXEdit.exe or related PDF-XChange Editor processes with access violation or null pointer exception details.PDFXEdit.exe) shortly after opening a document, particularly with faulting module references to the file-reading component.Users should update PDF-XChange Editor to a version beyond 10.7.3.401 that addresses this vulnerability; check the PDF-XChange website for the latest patched release. As a workaround, avoid opening PDF or document files from untrusted sources with the affected version. Organizations using automated document processing pipelines with PDF-XChange Editor should validate input files before processing or temporarily disable processing of externally sourced files until a patch is applied (Jeroscope Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."