
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6646 is a use-after-free (UAF) information disclosure vulnerability in PDF-XChange Editor's U3D file parsing component. It affects PDF-XChange Editor and PDF-XChange PDF-Tools version 10.5.2.395. The vulnerability was reported to the vendor on March 12, 2025, and publicly disclosed on June 25, 2025, via a coordinated release. It carries a CVSS v3.0 base score of 3.3 (Low) (ZDI Advisory, PDF-XChange Bulletins).
The vulnerability is classified as CWE-416 (Use After Free) and stems from the failure to validate the existence of an object before performing operations on it during U3D file parsing within PDF-XChange Editor. An attacker can craft a malicious U3D-embedded file or web page that, when opened by a victim, triggers the use-after-free condition, leading to a read of freed memory. While the direct impact is limited to information disclosure, the vulnerability can be chained with other flaws to achieve arbitrary code execution in the context of the current process (ZDI Advisory).
Successful exploitation results in a low-confidentiality-impact information disclosure, allowing an attacker to read sensitive data from freed memory regions. Integrity and availability are not directly affected. However, the disclosed memory contents could be leveraged as a building block — combined with other vulnerabilities — to achieve arbitrary code execution within the PDF-XChange Editor process context (ZDI Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. Exploitation requires user interaction — the target must open a malicious file or visit a malicious page. The EPSS score is approximately 0.03%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (ZDI Advisory).
PDF-XChange has released a patch addressing this vulnerability; users should update PDF-XChange Editor and PDF-XChange PDF-Tools to the latest version beyond 10.5.2.395 as detailed in the vendor's security bulletins. As interim measures, users should avoid opening PDF or U3D files from untrusted or unknown sources, and consider implementing application whitelisting. Details on the patched version are available at the PDF-XChange security bulletins page (PDF-XChange Bulletins).
The vulnerability was discovered and reported by Mat Powell of Trend Micro Zero Day Initiative, which coordinated disclosure with PDF-XChange. No significant broader community or media reactions have been identified beyond standard vulnerability database aggregation (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."