CVE-2025-66495
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66495 is a use-after-free vulnerability in the annotation handling component of Foxit PDF Reader and PDF Editor, affecting versions before 2025.2.1, 14.0.1, and 13.2.1 on Windows and macOS. When a user opens a specially crafted PDF containing malicious JavaScript, a pointer to already-freed memory may be accessed or dereferenced, potentially enabling remote code execution. The vulnerability was published on December 19, 2025, with the ZDI advisory (ZDI-25-1176) released the same day. It carries a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is a use-after-free condition (CWE-416) in Foxit's annotation handling subsystem, specifically triggered during JavaScript processing within PDF documents. When a maliciously crafted PDF is opened, the JavaScript engine accesses or dereferences a memory pointer that has already been freed, leading to memory corruption. The attack vector is local (the victim must open a malicious file), requires no privileges, but does require user interaction. A proof-of-concept is referenced in the ZDI advisory (ZDI Advisory).

Impact

Successful exploitation can result in arbitrary code execution on the victim's system with the privileges of the Foxit PDF Reader process, leading to high confidentiality, integrity, and availability impact. An attacker could leverage this to install malware, steal sensitive data, or pivot to other systems on the network. The vulnerability affects both Windows and macOS platforms, broadening the potential attack surface across enterprise and consumer environments (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing specially crafted JavaScript that manipulates Foxit's annotation handling to trigger a use-after-free condition — for example, by allocating and freeing annotation objects in a sequence that leaves a dangling pointer.
  2. Deliver the payload: Distribute the malicious PDF via email attachment, web download, or other social engineering vectors targeting Foxit PDF Reader users on Windows or macOS.
  3. Victim opens the PDF: The target opens the file in a vulnerable version of Foxit PDF Reader (before 2025.2.1, 14.0.1, or 13.2.1), triggering JavaScript execution.
  4. Trigger use-after-free: The crafted JavaScript causes the annotation handler to access freed memory, resulting in memory corruption.
  5. Achieve code execution: By controlling the freed memory region (e.g., via heap spray), the attacker redirects execution flow to a shellcode payload, achieving arbitrary code execution in the context of the Foxit process (ZDI Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Foxit PDF Reader process (e.g., FoxitPDFReader.exe or FoxitPDFEditor.exe) to unknown external IP addresses or domains shortly after opening a PDF file.
  • Process: Unusual child processes spawned by Foxit PDF Reader, such as cmd.exe, powershell.exe, curl, or wget; unexpected process injection into other running processes.
  • File System: New or modified executable files, scripts, or scheduled tasks created in user-writable directories (e.g., %APPDATA%, %TEMP%) following PDF file opening.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing Foxit PDF Reader with access violation or heap corruption errors; EDR alerts for memory corruption events associated with Foxit processes.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: Foxit PDF Reader and PDF Editor 2025.2.1, 14.0.1, and 13.2.1 for both Windows and macOS. Users should update immediately via the Foxit website or built-in updater. As a temporary workaround, disabling JavaScript execution in Foxit PDF Reader settings (Preferences > JavaScript > uncheck "Enable JavaScript Actions") will prevent exploitation. Additionally, organizations should implement email and web filtering to block suspicious PDF attachments and exercise caution when opening PDFs from untrusted sources (Foxit Security Bulletins, ZDI Advisory).

Community reactions

Heise reported on the Foxit PDF updates, noting the closure of "highly risky security vulnerabilities" and urging users to update immediately (Heise News). The vulnerability was also covered in weekly threat landscape digests and security news aggregators, reflecting moderate community interest. No significant vendor statements beyond the official security bulletin or notable researcher commentary beyond the ZDI advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management