216.73.216.6

CVE-2025-66493

· Published 19/12/2025 07:16 · Modified 23/12/2025 17:36

Labels: CVE-2025-66493 14984358-7092-470d-8f34-ade47a7658a22025-12-19CVE-2025-66493

Essential information

Published
19/12/2025 07:16
Modified
23/12/2025 17:36
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
14984358-7092-470d-8f34-ade47a7658a2
NVD
View on NVD

Affected products (CPE)

ProductCPE
foxit / pdf editor cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
foxit / pdf editor cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
foxit / pdf editor cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
foxit / pdf editor cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
foxit / pdf editor cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
foxit / pdf reader cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
microsoft / windows cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

References