CVE-2025-66494
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66494 is a use-after-free vulnerability in the PDF file parsing component of Foxit PDF Reader and Foxit PDF Editor on Windows. When a PDF object managed by multiple parent objects is freed while still being referenced, a remote attacker can potentially execute arbitrary code by tricking a user into opening a malicious PDF document. Affected versions include Foxit PDF Reader before 2025.2.1, Foxit PDF Editor before 13.2.1, 14.0.1, and 2025.2.1 (covering version branches 13.x, 14.x, 2023.x, 2024.x, and 2025.x). The vulnerability was published on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring in Foxit's PDF file parsing engine when a PDF object is simultaneously managed by multiple parent objects. When one parent frees the object, the other parent retains a dangling reference to the now-freed memory region. An attacker can craft a specially structured PDF document that triggers this condition, potentially allowing them to control the freed memory and redirect execution flow to attacker-controlled code. Exploitation requires user interaction — the victim must open the malicious PDF file — but no privileges are required, and the attack vector is local (the file must be delivered to and opened on the target system) (ZDI Advisory).

Impact

Successful exploitation grants an attacker arbitrary code execution in the context of the user running Foxit PDF Reader or PDF Editor, with high impact to confidentiality, integrity, and availability. This could enable an attacker to steal sensitive information, install malware or ransomware, modify or delete critical data, and use the compromised endpoint as a pivot point for lateral movement within a network. The scope is limited to the affected system (unchanged scope), but the combination of full CIA triad impact makes this a significant risk for enterprise environments where PDF documents are routinely exchanged (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft malicious PDF: Create a specially structured PDF document that contains objects with multiple parent references, designed to trigger the use-after-free condition in Foxit's PDF parsing engine when the document is processed.
  2. Deliver the payload: Distribute the malicious PDF to the target via phishing email, malicious download link, or other social engineering methods, exploiting the fact that PDF files are commonly trusted and opened without scrutiny.
  3. Trigger the vulnerability: When the victim opens the PDF in a vulnerable version of Foxit PDF Reader or PDF Editor, the parser processes the malformed object structure, causing one parent to free the shared PDF object while another parent still holds a reference to it.
  4. Memory manipulation: The attacker's crafted PDF leverages the dangling pointer to write attacker-controlled data into the freed memory region, enabling control over program execution flow.
  5. Achieve code execution: By redirecting execution to a shellcode or ROP chain embedded in the PDF, the attacker executes arbitrary code in the context of the victim user, potentially establishing persistence, exfiltrating data, or deploying additional malware (ZDI Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Foxit PDF Reader/Editor process (FoxitPDFReader.exe or FoxitPDFEditor.exe) to unknown external IP addresses or domains shortly after opening a PDF file.
  • Process: Unusual child processes spawned by FoxitPDFReader.exe or FoxitPDFEditor.exe, such as cmd.exe, powershell.exe, mshta.exe, or other scripting engines.
  • File System: New or modified files in user temp directories (%TEMP%, %APPDATA%) created by the Foxit process; unexpected executables or scripts dropped to disk following PDF opening.
  • Logs: Windows Event Logs showing application crashes or access violations in Foxit processes (Event ID 1000/1001); security logs recording new process creation events with Foxit as the parent process.
  • Memory: Crash dumps or Dr. Watson logs associated with Foxit PDF Reader/Editor indicating heap corruption or access violations in the PDF parsing module.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: update Foxit PDF Reader to version 2025.2.1 or later, Foxit PDF Editor to 13.2.1, 14.0.1, or 2025.2.1 (depending on the installed branch). Users should apply updates immediately via the Foxit software updater or by downloading the latest version from the official Foxit website. As interim mitigations, disable PDF preview panes in email clients (e.g., Outlook), avoid opening PDF files from untrusted or unexpected sources, and consider deploying endpoint detection and response (EDR) solutions to monitor for suspicious process behavior originating from PDF reader applications (Foxit Security Bulletins, ZDI Advisory).

Community reactions

Heise (a German technology news outlet) covered the Foxit PDF updates, noting the closure of highly risky security vulnerabilities in their December 2025 reporting (Heise News). The vulnerability was also highlighted in the Hawk-Eye weekly threat landscape digest for Week 52 of 2025, indicating moderate community awareness. No significant vendor statements beyond the security bulletin or notable individual researcher commentary beyond the ZDI advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management