
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66499 is a heap-based buffer overflow vulnerability in Foxit PDF Reader and Foxit PDF Editor caused by an integer overflow during JBIG2 image buffer size calculation when parsing specially crafted PDF files. It was published on December 19, 2025, with the Zero Day Initiative advisory (ZDI-25-1180) released the same day. Affected products include Foxit PDF Reader (versions up to 2025.2.1) and Foxit PDF Editor (versions up to 13.2.1, 14.0.1, and 2025.2.1 across multiple release branches). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (ZDI Advisory, Foxit Security Bulletins).
The root cause is an integer overflow (CWE-190) during the calculation of the image buffer size when processing JBIG2-encoded data embedded in PDF files, which leads to a heap-based buffer overflow (CAPEC-92: Forced Integer Overflow). An attacker crafts a malicious PDF containing specially structured JBIG2 data that triggers the overflow when the file is opened by the victim, causing the application to write beyond the allocated heap buffer. Exploitation requires user interaction — the victim must open the malicious PDF — but no privileges are required on the attacker's side. A proof-of-concept advisory is publicly available from the Zero Day Initiative (ZDI Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who tricks a user into opening a malicious PDF could fully compromise the victim's workstation, potentially enabling data theft, malware installation, or lateral movement within a network. Both Foxit PDF Reader and Foxit PDF Editor across multiple version branches are affected, broadening the potential attack surface (ZDI Advisory, Foxit Security Bulletins).
%TEMP%) or application data folders shortly after opening a PDF; new or modified executables in user-writable locations.FoxitPDFReader.exe or FoxitPDFEditor.exe (e.g., cmd.exe, powershell.exe, curl.exe, or scripting engines); crashes or abnormal termination of Foxit processes with heap corruption error codes..dmp) generated in %LOCALAPPDATA%\CrashDumps or similar locations referencing Foxit modules.Foxit has released patched versions addressing this vulnerability; users should update Foxit PDF Reader and Foxit PDF Editor to versions beyond 2025.2.1, 13.2.1, and 14.0.1 respectively. As interim mitigations, organizations should disable PDF JavaScript and macros if not required, implement application whitelisting, and train users to avoid opening PDFs from untrusted sources. Strict PDF file validation at email gateways and web proxies can also reduce exposure (Foxit Security Bulletins).
Heise reported on the Foxit PDF updates closing highly risky security vulnerabilities, noting the significance of the JBIG2 parsing flaw (Heise). The vulnerability was also picked up in the Hawk-Eye weekly threat landscape digest for Week 52 of 2025, indicating moderate community interest. Social media activity was limited, with automated CVE tracking accounts on Bluesky and Mastodon (CIRCL) noting the disclosure. Overall community sentiment reflects concern given the public PoC availability, but no widespread alarm due to the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."