CVE-2025-66498
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66498 is a memory corruption vulnerability in the 3D annotation handling of Foxit PDF Reader and PDF Editor, caused by insufficient bounds checking when parsing U3D/PRC data embedded in PDF files. When a user opens a specially crafted PDF containing malformed PRC content, out-of-bounds memory access occurs, potentially enabling arbitrary code execution. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (multiple version ranges up to 2025.2.1). The vulnerability was disclosed on December 19, 2025, with a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), stemming from insufficient bounds checking in the code path responsible for parsing U3D and PRC 3D annotation data within PDF files. An attacker crafts a PDF with malformed PRC content that triggers out-of-bounds memory access when the 3D annotation renderer processes the data. Exploitation requires local delivery of the malicious PDF and user interaction (opening the file), with no privileges required. A proof-of-concept is referenced in the Zero Day Initiative advisory ZDI-25-1179 (ZDI Advisory).

Impact

Successful exploitation can result in high-impact confidentiality, integrity, and availability consequences on the affected system, including potential arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. Memory corruption may allow an attacker to read sensitive data from process memory, overwrite critical memory structures, or crash the application. The scope is limited to the local system, but code execution could enable further lateral movement or data exfiltration depending on the user's privileges (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft malicious PDF: Create a PDF file containing a specially malformed 3D annotation with invalid or oversized U3D/PRC data structures that violate expected bounds during parsing.
  2. Deliver the file: Distribute the malicious PDF to the target via email attachment, web download, or other social engineering means, targeting users running a vulnerable version of Foxit PDF Reader or PDF Editor.
  3. Trigger user interaction: Induce the victim to open the PDF file in Foxit PDF Reader or Editor. The 3D annotation renderer automatically processes the embedded PRC/U3D content upon opening.
  4. Trigger memory corruption: The insufficient bounds checking in the 3D annotation handler causes an out-of-bounds read or write, corrupting heap or stack memory.
  5. Achieve code execution: By carefully controlling the malformed data, an attacker may redirect execution flow to attacker-controlled code, achieving arbitrary code execution in the context of the victim user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected PDF files with embedded 3D annotations (U3D/PRC content) received from unknown or untrusted sources; suspicious files dropped in temp directories by the Foxit process.
  • Process: Foxit PDF Reader or Editor spawning unexpected child processes (e.g., cmd.exe, powershell.exe, curl, wget) following PDF file open events; crashes or abnormal termination of Foxit processes.
  • Logs: Application crash logs or Windows Error Reporting entries referencing Foxit PDF Reader/Editor with memory access violations; event log entries showing abnormal process creation from Foxit executables.
  • Network: Unexpected outbound network connections originating from the Foxit PDF Reader/Editor process to unknown external IP addresses following document open events.

Mitigation and workarounds

Foxit has released patches addressing this vulnerability. Users should update to versions beyond the affected ranges: Foxit PDF Reader beyond 2025.2.1, and Foxit PDF Editor beyond 2025.2.1 (or 13.2.1, 14.0.1, 2023.3.0, 2024.4.1 depending on the installed branch). As interim mitigations, users should avoid opening PDF files from untrusted sources, implement email and download filtering to block unexpected PDF attachments, and consider application whitelisting. Updates are available via the Foxit security bulletins page (Foxit Security Bulletins).

Community reactions

Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities shortly after disclosure (Heise). The vulnerability was also covered in the Hawk Eye weekly threat landscape digest for Week 52 of 2025. Community aggregators including VulnDB, CIRCL Vulnerability Lookup, and INCIBE-CERT flagged the advisory, indicating standard industry awareness without significant controversy or notable researcher commentary beyond the ZDI disclosure.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management