
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66494 is a use-after-free vulnerability in the PDF file parsing component of Foxit PDF Reader and Foxit PDF Editor on Windows. When a PDF object managed by multiple parent objects is freed while still being referenced, a remote attacker can potentially execute arbitrary code by tricking a user into opening a malicious PDF document. Affected versions include Foxit PDF Reader before 2025.2.1, Foxit PDF Editor before 13.2.1, 14.0.1, and 2025.2.1 (covering version branches 13.x, 14.x, 2023.x, 2024.x, and 2025.x). The vulnerability was published on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Foxit's PDF file parsing engine when a PDF object is simultaneously managed by multiple parent objects. When one parent frees the object, the other parent retains a dangling reference to the now-freed memory region. An attacker can craft a specially structured PDF document that triggers this condition, potentially allowing them to control the freed memory and redirect execution flow to attacker-controlled code. Exploitation requires user interaction — the victim must open the malicious PDF file — but no privileges are required, and the attack vector is local (the file must be delivered to and opened on the target system) (ZDI Advisory).
Successful exploitation grants an attacker arbitrary code execution in the context of the user running Foxit PDF Reader or PDF Editor, with high impact to confidentiality, integrity, and availability. This could enable an attacker to steal sensitive information, install malware or ransomware, modify or delete critical data, and use the compromised endpoint as a pivot point for lateral movement within a network. The scope is limited to the affected system (unchanged scope), but the combination of full CIA triad impact makes this a significant risk for enterprise environments where PDF documents are routinely exchanged (ZDI Advisory, Foxit Security Bulletins).
FoxitPDFReader.exe or FoxitPDFEditor.exe) to unknown external IP addresses or domains shortly after opening a PDF file.FoxitPDFReader.exe or FoxitPDFEditor.exe, such as cmd.exe, powershell.exe, mshta.exe, or other scripting engines.%TEMP%, %APPDATA%) created by the Foxit process; unexpected executables or scripts dropped to disk following PDF opening.Foxit has released patched versions addressing this vulnerability: update Foxit PDF Reader to version 2025.2.1 or later, Foxit PDF Editor to 13.2.1, 14.0.1, or 2025.2.1 (depending on the installed branch). Users should apply updates immediately via the Foxit software updater or by downloading the latest version from the official Foxit website. As interim mitigations, disable PDF preview panes in email clients (e.g., Outlook), avoid opening PDF files from untrusted or unexpected sources, and consider deploying endpoint detection and response (EDR) solutions to monitor for suspicious process behavior originating from PDF reader applications (Foxit Security Bulletins, ZDI Advisory).
Heise (a German technology news outlet) covered the Foxit PDF updates, noting the closure of highly risky security vulnerabilities in their December 2025 reporting (Heise News). The vulnerability was also highlighted in the Hawk-Eye weekly threat landscape digest for Week 52 of 2025, indicating moderate community awareness. No significant vendor statements beyond the security bulletin or notable individual researcher commentary beyond the ZDI advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."