
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66496 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor caused by insufficient bounds checking when parsing PRC (Product Representation Compact) data within 3D annotations. When a user opens a specially crafted PDF file containing malformed PRC content, out-of-bounds memory access occurs, potentially leading to arbitrary code execution or application crashes. Affected products include Foxit PDF Reader up to version 2025.2.1.33197, and Foxit PDF Editor across multiple version branches (13.x up to 13.2.1.23955, 14.x up to 14.0.1.33197, 2023.x up to 2023.3.0.23028, 2024.x up to 2024.4.1.27687, and 2025.x up to 2025.2.1.33197). The vulnerability was published on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) per ZDI, though Foxit's own advisory assigns a lower score of 5.3 (Medium) (ZDI Advisory, Foxit Security Bulletins).
The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), arising from insufficient bounds checking in the 3D annotation parsing subsystem when processing PRC data embedded in PDF files. An attacker crafts a malformed PDF with specially structured PRC content that triggers out-of-bounds memory access during parsing. The attack vector is local (the victim must open the malicious file), requires user interaction, and no privileges are needed. A proof-of-concept has been published by the Zero Day Initiative (ZDI Advisory).
Successful exploitation could allow an attacker to execute arbitrary code in the context of the current user or cause the application to crash, impacting confidentiality, integrity, and availability. The vulnerability is triggered by user interaction — specifically opening a maliciously crafted PDF — making it suitable for phishing or drive-by download campaigns targeting Foxit PDF users. The scope is limited to the affected application and user context, with no direct lateral movement capability, but code execution could serve as an initial foothold for further compromise (ZDI Advisory, Foxit Security Bulletins).
cmd.exe, powershell.exe, curl) on Windows.FoxitPDFReader.exe or FoxitPDFEditor.exe; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or Foxit's own crash reporting directory.Foxit has released patches addressing this vulnerability; users should update Foxit PDF Reader and PDF Editor to versions beyond the affected ranges (i.e., versions released after 2025.2.1.33197 for the 2025 branch, 14.0.1.33197 for the 14.x branch, etc.) by consulting Foxit's security bulletins. As interim mitigations, users should avoid opening PDF files from untrusted or unknown sources, implement email and web filtering to block malicious PDF delivery, and use application whitelisting. Keeping all software and operating systems up to date is also recommended (Foxit Security Bulletins).
Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities, noting the significance of the patches for enterprise users (Heise). The vulnerability was also covered in Hawk-Eye's weekly threat landscape digest for Week 52 of 2025, indicating moderate community awareness. No notable individual researcher commentary or significant social media debate beyond standard CVE tracking activity has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."