216.73.217.22

CVE-2025-32451

· Published 13/08/2025 14:15 · Modified 13/08/2025 17:33

Labels: CVE-2025-32451 2025-08-13CVE-2025-32451CWE-824[email protected]

Essential information

Published
13/08/2025 14:15
Modified
13/08/2025 17:33
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
foxit / foxit reader cpe:2.3:a:foxit:foxit_reader:2025.1.0.27937:*:*:*:*:*:*:*

References