CVE-2025-66499
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-66499 is a heap-based buffer overflow vulnerability in Foxit PDF Reader and Foxit PDF Editor caused by an integer overflow during JBIG2 image buffer size calculation when parsing specially crafted PDF files. It was published on December 19, 2025, with the Zero Day Initiative advisory (ZDI-25-1180) released the same day. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (versions up to 13.2.1, 14.0.1, and 2025.2.1 across multiple release branches). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).

Technical details

The root cause is an integer overflow (CWE-190) during the calculation of the image buffer size when processing JBIG2-encoded data embedded in PDF files, which leads to a heap-based buffer overflow (CAPEC-92: Forced Integer Overflow). An attacker crafts a malicious PDF containing specially structured JBIG2 data that triggers the overflow when the file is opened by the victim, causing the application to write beyond the allocated heap buffer. Exploitation requires user interaction — the victim must open the malicious PDF — but no privileges are required on the attacker's side. A proof-of-concept advisory is publicly available from the Zero Day Initiative (ZDI Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who tricks a user into opening a malicious PDF could fully compromise the victim's workstation, potentially enabling data theft, malware installation, or lateral movement within a network. Both Foxit PDF Reader and Foxit PDF Editor across multiple version branches are affected, broadening the potential attack surface (ZDI Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft malicious PDF: Create a PDF file containing specially crafted JBIG2 image data designed to trigger an integer overflow in Foxit's image buffer size calculation routine.
  2. Deliver the payload: Distribute the malicious PDF via phishing email, malicious download link, or other social engineering methods targeting users of Foxit PDF Reader or PDF Editor.
  3. Trigger the vulnerability: When the victim opens the PDF in a vulnerable version of Foxit PDF Reader or PDF Editor, the JBIG2 parser performs an integer overflow during buffer size calculation, resulting in an undersized heap allocation.
  4. Heap buffer overflow: The application writes JBIG2 image data beyond the allocated buffer boundary, corrupting adjacent heap memory.
  5. Achieve code execution: By controlling the heap layout and overflow content, the attacker overwrites critical data structures (e.g., function pointers or vtable entries) to redirect execution flow and run arbitrary code with the privileges of the victim user (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected files written to user temp directories (e.g., %TEMP%) or application data folders shortly after opening a PDF; new or modified executables in user-writable locations.
  • Process: Unusual child processes spawned by FoxitPDFReader.exe or FoxitPDFEditor.exe (e.g., cmd.exe, powershell.exe, curl.exe, or scripting engines); crashes or abnormal termination of Foxit processes with heap corruption error codes.
  • Network: Unexpected outbound network connections from Foxit PDF Reader/Editor processes to external IP addresses or domains, particularly shortly after opening a PDF file.
  • Logs: Windows Event Log entries showing application crashes (Event ID 1000/1001) for Foxit processes; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps or similar locations referencing Foxit modules.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability; users should update Foxit PDF Reader and Foxit PDF Editor to versions beyond 2025.2.1, 13.2.1, and 14.0.1 respectively. As interim mitigations, organizations should disable PDF JavaScript and macros if not required, implement application whitelisting, and train users to avoid opening PDFs from untrusted sources. Strict PDF file validation at email gateways and web proxies can also reduce exposure (Foxit Security Bulletins).

Community reactions

Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities, noting the significance of the JBIG2 parsing flaw (Heise). The vulnerability was also picked up in the Hawk-Eye weekly threat landscape digest for Week 52 of 2025, indicating moderate community interest. Social media activity was limited, with automated CVE tracking accounts on Bluesky and Mastodon (CIRCL) noting the disclosure. Overall community sentiment reflects concern given the public PoC availability, but no widespread alarm due to the absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management