CVE-2025-66496
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66496 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor caused by insufficient bounds checking when parsing PRC (Product Representation Compact) data within 3D annotations. When a user opens a specially crafted PDF file containing malformed PRC content, out-of-bounds memory access occurs, potentially leading to arbitrary code execution or application crashes. Affected products include Foxit PDF Reader up to version 2025.2.1.33197, and Foxit PDF Editor across multiple version branches (13.x up to 13.2.1.23955, 14.x up to 14.0.1.33197, 2023.x up to 2023.3.0.23028, 2024.x up to 2024.4.1.27687, and 2025.x up to 2025.2.1.33197). The vulnerability was published on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) per ZDI, though Foxit's own advisory assigns a lower score of 5.3 (Medium) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), arising from insufficient bounds checking in the 3D annotation parsing subsystem when processing PRC data embedded in PDF files. An attacker crafts a malformed PDF with specially structured PRC content that triggers out-of-bounds memory access during parsing. The attack vector is local (the victim must open the malicious file), requires user interaction, and no privileges are needed. A proof-of-concept has been published by the Zero Day Initiative (ZDI Advisory).

Impact

Successful exploitation could allow an attacker to execute arbitrary code in the context of the current user or cause the application to crash, impacting confidentiality, integrity, and availability. The vulnerability is triggered by user interaction — specifically opening a maliciously crafted PDF — making it suitable for phishing or drive-by download campaigns targeting Foxit PDF users. The scope is limited to the affected application and user context, with no direct lateral movement capability, but code execution could serve as an initial foothold for further compromise (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft malicious PDF: Create a PDF file containing a 3D annotation with malformed or specially structured PRC data designed to trigger out-of-bounds memory access during parsing.
  2. Deliver the file: Distribute the malicious PDF to the target via phishing email, malicious website, or other social engineering means, relying on the victim using a vulnerable version of Foxit PDF Reader or PDF Editor.
  3. Trigger parsing: The victim opens the PDF file in a vulnerable Foxit application, causing the 3D annotation handler to parse the embedded PRC content.
  4. Memory corruption: Insufficient bounds checking causes an out-of-bounds read or write, corrupting heap or stack memory in the application process.
  5. Achieve code execution or crash: Depending on the crafted payload and memory layout, the attacker may achieve arbitrary code execution in the context of the victim user, or at minimum cause a denial-of-service crash (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected PDF files received via email or downloaded from untrusted sources containing embedded 3D/PRC annotation data; suspicious files in temp directories created by Foxit processes.
  • Process: Foxit PDF Reader or Editor process crashing unexpectedly (application crash logs/minidumps) after opening a PDF; unusual child processes spawned by Foxit (e.g., cmd.exe, powershell.exe, curl) on Windows.
  • Logs: Windows Event Logs showing application faults (Event ID 1000) for FoxitPDFReader.exe or FoxitPDFEditor.exe; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or Foxit's own crash reporting directory.
  • Network: Unexpected outbound network connections from Foxit processes to unknown external IP addresses following the opening of a PDF file.

Mitigation and workarounds

Foxit has released patches addressing this vulnerability; users should update Foxit PDF Reader and PDF Editor to versions beyond the affected ranges (i.e., versions released after 2025.2.1.33197 for the 2025 branch, 14.0.1.33197 for the 14.x branch, etc.) by consulting Foxit's security bulletins. As interim mitigations, users should avoid opening PDF files from untrusted or unknown sources, implement email and web filtering to block malicious PDF delivery, and use application whitelisting. Keeping all software and operating systems up to date is also recommended (Foxit Security Bulletins).

Community reactions

Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities, noting the significance of the patches for enterprise users (Heise). The vulnerability was also covered in Hawk-Eye's weekly threat landscape digest for Week 52 of 2025, indicating moderate community awareness. No notable individual researcher commentary or significant social media debate beyond standard CVE tracking activity has been observed.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management