
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66495 is a use-after-free vulnerability in the annotation handling component of Foxit PDF Reader and PDF Editor, affecting versions before 2025.2.1, 14.0.1, and 13.2.1 on Windows and macOS. When a user opens a specially crafted PDF containing malicious JavaScript, a pointer to already-freed memory may be accessed or dereferenced, potentially enabling remote code execution. The vulnerability was published on December 19, 2025, with the ZDI advisory (ZDI-25-1176) released the same day. It carries a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).
The root cause is a use-after-free condition (CWE-416) in Foxit's annotation handling subsystem, specifically triggered during JavaScript processing within PDF documents. When a maliciously crafted PDF is opened, the JavaScript engine accesses or dereferences a memory pointer that has already been freed, leading to memory corruption. The attack vector is local (the victim must open a malicious file), requires no privileges, but does require user interaction. A proof-of-concept is referenced in the ZDI advisory (ZDI Advisory).
Successful exploitation can result in arbitrary code execution on the victim's system with the privileges of the Foxit PDF Reader process, leading to high confidentiality, integrity, and availability impact. An attacker could leverage this to install malware, steal sensitive data, or pivot to other systems on the network. The vulnerability affects both Windows and macOS platforms, broadening the potential attack surface across enterprise and consumer environments (ZDI Advisory, Foxit Security Bulletins).
FoxitPDFReader.exe or FoxitPDFEditor.exe) to unknown external IP addresses or domains shortly after opening a PDF file.cmd.exe, powershell.exe, curl, or wget; unexpected process injection into other running processes.%APPDATA%, %TEMP%) following PDF file opening.Foxit has released patched versions addressing this vulnerability: Foxit PDF Reader and PDF Editor 2025.2.1, 14.0.1, and 13.2.1 for both Windows and macOS. Users should update immediately via the Foxit website or built-in updater. As a temporary workaround, disabling JavaScript execution in Foxit PDF Reader settings (Preferences > JavaScript > uncheck "Enable JavaScript Actions") will prevent exploitation. Additionally, organizations should implement email and web filtering to block suspicious PDF attachments and exercise caution when opening PDFs from untrusted sources (Foxit Security Bulletins, ZDI Advisory).
Heise reported on the Foxit PDF updates, noting the closure of "highly risky security vulnerabilities" and urging users to update immediately (Heise News). The vulnerability was also covered in weekly threat landscape digests and security news aggregators, reflecting moderate community interest. No significant vendor statements beyond the official security bulletin or notable researcher commentary beyond the ZDI advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."