CVE-2025-66497
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66497 is a memory corruption vulnerability in Foxit PDF Reader and PDF Editor caused by insufficient bounds checking when parsing PRC (Product Representation Compact) data within 3D annotations. When a user opens a specially crafted PDF file containing malformed PRC content, out-of-bounds memory access occurs, resulting in memory corruption. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (versions up to 13.2.1, 14.0.1, and 2025.2.1 across multiple release branches). The vulnerability was published on December 19, 2025. It carries a CVSS v3.1 base score of 7.8 (High) per ZDI, though Foxit's own advisory scores it at 5.3 (Medium) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), stemming from the application's failure to properly validate buffer boundaries when processing PRC data embedded in 3D PDF annotations. An attacker exploits this by crafting a PDF file with malformed PRC content that, when parsed by the Foxit rendering engine, causes the application to read or write memory outside the intended buffer. The attack vector is local (the file must be present on the victim's system), requires no privileges, but does require user interaction — specifically, the user must open the malicious PDF. A proof-of-concept advisory was published by the Zero Day Initiative (ZDI Advisory).

Impact

Successful exploitation can result in high impacts to confidentiality, integrity, and availability on the affected system, as reflected in the ZDI CVSS scoring. An attacker who tricks a user into opening a malicious PDF could achieve information disclosure, integrity manipulation of application memory, and potential disruption of application availability. While the scope is limited to the local user context (no privilege escalation to other systems is implied), the memory corruption could theoretically be leveraged for arbitrary code execution in the context of the Foxit process (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing a 3D annotation with specially malformed PRC data that violates the expected buffer boundaries during parsing.
  2. Deliver the file: Distribute the malicious PDF to the target via email attachment, web download, or other file-sharing mechanism, relying on social engineering to prompt the user to open it.
  3. Trigger parsing: When the victim opens the PDF in a vulnerable version of Foxit PDF Reader or PDF Editor, the 3D annotation renderer attempts to parse the PRC content.
  4. Trigger memory corruption: The insufficient bounds checking causes an out-of-bounds read or write, corrupting application memory in the context of the Foxit process.
  5. Achieve objective: Depending on exploit reliability and memory layout, the attacker may achieve information disclosure (reading sensitive memory contents), application crash (denial of service), or potentially arbitrary code execution within the Foxit process context (ZDI Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited PDF files containing 3D annotations (PRC data) in user download folders, temp directories, or email attachment staging areas.
  • Process: Foxit PDF Reader or PDF Editor process (FoxitPDFReader.exe, FoxitPDFEditor.exe) crashing unexpectedly or generating application error logs when opening specific PDF files.
  • Logs: Windows Event Logs (Application) showing faulting module entries for Foxit executables with access violation (0xC0000005) exception codes.
  • Network: Outbound connections from the Foxit process to unexpected external hosts shortly after opening a PDF file, which may indicate post-exploitation activity if code execution is achieved.

Mitigation and workarounds

Foxit has released patches addressing this vulnerability. Users should update to the latest available versions: Foxit PDF Reader beyond 2025.2.1 and Foxit PDF Editor beyond the affected branches (13.2.1, 14.0.1, and 2025.2.1). As interim mitigations, users should avoid opening PDF files from untrusted or unknown sources, and organizations should implement email and web filtering to block potentially malicious PDF attachments. Application-level controls such as Protected Mode or sandboxing (where available) can also reduce exposure (Foxit Security Bulletins).

Community reactions

Heise reported on the Foxit PDF updates, noting that the patches close "highly risky security vulnerabilities," reflecting broader media attention to this and related Foxit flaws disclosed in December 2025 (Heise News). The vulnerability was also highlighted in a weekly threat landscape digest for Week 52 of 2025, indicating moderate community tracking interest. No significant researcher controversy or vendor dispute regarding the severity scoring discrepancy (ZDI: 7.8 High vs. Foxit: 5.3 Medium) has been publicly noted.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management