
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66497 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor caused by insufficient bounds checking when parsing PRC (Product Representation Compact) data within 3D annotations. When a user opens a specially crafted PDF file containing malformed PRC content, out-of-bounds memory access occurs, resulting in memory corruption. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (versions up to 13.2.1, 14.0.1, and 2025.2.1 across multiple release branches). The vulnerability was published on December 19, 2025. It carries a CVSS v3.1 base score of 7.8 (High) per ZDI, though Foxit's own advisory scores it at 5.3 (Medium) (ZDI Advisory, Foxit Security Bulletins).
The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), stemming from the application's failure to properly validate buffer boundaries when processing PRC data embedded in 3D PDF annotations. An attacker exploits this by crafting a PDF file with malformed PRC content that, when parsed by the Foxit rendering engine, causes the application to read or write memory outside the intended buffer. The attack vector is local (the file must be present on the victim's system), requires no privileges, but does require user interaction — specifically, the user must open the malicious PDF. A proof-of-concept advisory was published by the Zero Day Initiative (ZDI Advisory).
Successful exploitation can result in high impacts to confidentiality, integrity, and availability on the affected system, as reflected in the ZDI CVSS scoring. An attacker who tricks a user into opening a malicious PDF could achieve information disclosure, integrity manipulation of application memory, and potential disruption of application availability. While the scope is limited to the local user context (no privilege escalation to other systems is implied), the memory corruption could theoretically be leveraged for arbitrary code execution in the context of the Foxit process (ZDI Advisory, Foxit Security Bulletins).
FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or generating application error logs when opening specific PDF files.Foxit has released patches addressing this vulnerability. Users should update to the latest available versions: Foxit PDF Reader beyond 2025.2.1 and Foxit PDF Editor beyond the affected branches (13.2.1, 14.0.1, and 2025.2.1). As interim mitigations, users should avoid opening PDF files from untrusted or unknown sources, and organizations should implement email and web filtering to block potentially malicious PDF attachments. Application-level controls such as Protected Mode or sandboxing (where available) can also reduce exposure (Foxit Security Bulletins).
Heise reported on the Foxit PDF updates, noting that the patches close "highly risky security vulnerabilities," reflecting broader media attention to this and related Foxit flaws disclosed in December 2025 (Heise News). The vulnerability was also highlighted in a weekly threat landscape digest for Week 52 of 2025, indicating moderate community tracking interest. No significant researcher controversy or vendor dispute regarding the severity scoring discrepancy (ZDI: 7.8 High vs. Foxit: 5.3 Medium) has been publicly noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."