CVE-2025-69627
Nitro Pro vulnerability analysis and mitigation

Overview

CVE-2025-69627 is a heap use-after-free vulnerability in Nitro PDF Pro for Windows version 14.41.1.4, specifically within the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely; the freed pointer is subsequently passed into UI and logging helper functions, allowing downstream routines such as wcscmp() to process invalid or stale pointers. This can result in access violations and non-deterministic crashes. It was published on April 13, 2026, and carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory).

Technical details

The root cause is a CWE-416 (Use After Free) flaw in Nitro PDF Pro's JavaScript engine handling of the this.mailDoc() method. An internal XID object is allocated on the heap during method execution, freed prematurely, and then the dangling pointer is passed to UI and logging helper functions. Because the freed memory region may contain unpredictable heap data or remnants of attacker-controlled JavaScript strings, functions such as wcscmp() may dereference invalid or stale pointers. The vulnerability is triggered locally — an attacker can embed malicious JavaScript within a crafted PDF document to invoke the vulnerable code path. A researcher advisory is referenced at https://jeroscope.com/advisories/2025/jero-2025-016/ (GitHub Advisory).

Impact

Successful exploitation can result in access violations and non-deterministic application crashes, constituting a denial-of-service condition against the Nitro PDF Pro application. Due to the unpredictable state of freed heap memory — which may contain attacker-influenced data — there is a theoretical risk of non-deterministic code execution with high confidentiality, integrity, and availability impact, as reflected in the CVSS score. The scope is limited to the local system running the affected application, with no direct lateral movement capability, but code execution could enable further post-exploitation activity (GitHub Advisory).

Exploitability

There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.006% (0th percentile), indicating a very low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires delivering a crafted PDF with malicious JavaScript to a target running Nitro PDF Pro 14.41.1.4 on Windows.

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing embedded JavaScript that invokes the this.mailDoc() method in a manner that triggers the premature allocation and freeing of the internal XID object.
  2. Deliver the PDF: Social-engineer the target into opening the crafted PDF using Nitro PDF Pro 14.41.1.4 on Windows (e.g., via email attachment, download link, or shared file).
  3. Trigger the vulnerability: When the victim opens the PDF and the JavaScript executes, the this.mailDoc() method allocates and prematurely frees the XID object, leaving a dangling pointer.
  4. Exploit heap state: The freed pointer is passed to UI/logging helpers such as wcscmp(), which may process attacker-influenced heap data, leading to an access violation, crash, or — under favorable heap conditions — non-deterministic code execution (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected crashes or access violations in the Nitro PDF Pro process (nitro.exe or similar), particularly when opening PDF files from untrusted sources.
  • Logs: Windows Event Log entries (Application log) recording application crashes or faulting module errors associated with Nitro PDF Pro, especially referencing memory access violations.
  • File System: Presence of suspicious or unexpected PDF files received via email or downloaded from unknown sources that trigger crashes upon opening in Nitro PDF Pro.
  • Network: Outbound email activity initiated unexpectedly by Nitro PDF Pro (related to mailDoc() invocation) to unknown or unintended recipients.

Mitigation and workarounds

A patch has been made available as of April 13, 2026; users should apply the latest update from Nitro (https://nitro.com) immediately (GitHub Advisory). As interim mitigations, organizations should avoid opening PDF documents from untrusted sources in Nitro PDF Pro, and restrict or disable JavaScript execution within PDF applications where policy permits. Monitoring for unusual crashes or access violations in Nitro PDF Pro instances is also recommended.

Additional resources


SourceThis report was generated using AI

Related Nitro Pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69627HIGH8.4
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoNoApr 13, 2026
CVE-2024-35288HIGH7.8
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesOct 09, 2024
CVE-2025-69624HIGH7.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoNoApr 13, 2026
CVE-2025-66769HIGH7.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoNoApr 13, 2026
CVE-2025-67825MEDIUM5.5
  • Nitro Pro logoNitro Pro
  • cpe:2.3:a:gonitro:nitro_pdf_pro
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management