
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66498 is a memory corruption vulnerability in the 3D annotation handling of Foxit PDF Reader and PDF Editor, caused by insufficient bounds checking when parsing U3D/PRC data embedded in PDF files. When a user opens a specially crafted PDF containing malformed PRC content, out-of-bounds memory access occurs, potentially enabling arbitrary code execution. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (multiple version ranges up to 2025.2.1). The vulnerability was disclosed on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).
The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), stemming from insufficient bounds checking in the code path responsible for parsing U3D and PRC 3D annotation data within PDF files. An attacker crafts a PDF with malformed PRC content that triggers out-of-bounds memory access when the 3D annotation renderer processes the data. Exploitation requires local delivery of the malicious PDF and user interaction (opening the file), with no privileges required. A proof-of-concept is referenced in the Zero Day Initiative advisory ZDI-25-1179 (ZDI Advisory).
Successful exploitation can result in high-impact confidentiality, integrity, and availability consequences on the affected system, including potential arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. Memory corruption may allow an attacker to read sensitive data from process memory, overwrite critical memory structures, or crash the application. The scope is limited to the local system, but code execution could enable further lateral movement or data exfiltration depending on the user's privileges (ZDI Advisory, Foxit Security Bulletins).
cmd.exe, powershell.exe, curl, wget) following PDF file open events; crashes or abnormal termination of Foxit processes.Foxit has released patches addressing this vulnerability. Users should update to versions beyond the affected ranges: Foxit PDF Reader beyond 2025.2.1, and Foxit PDF Editor beyond 2025.2.1 (or 13.2.1, 14.0.1, 2023.3.0, 2024.4.1 depending on the installed branch). As interim mitigations, users should avoid opening PDF files from untrusted sources, implement email and download filtering to block unexpected PDF attachments, and consider application whitelisting. Updates are available via the Foxit security bulletins page (Foxit Security Bulletins).
Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities shortly after disclosure (Heise). The vulnerability was also covered in the Hawk Eye weekly threat landscape digest for Week 52 of 2025. Community aggregators including VulnDB, CIRCL Vulnerability Lookup, and INCIBE-CERT flagged the advisory, indicating standard industry awareness without significant controversy or notable researcher commentary beyond the ZDI disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."