VYPR
High severity7.8NVD Advisory· Published Dec 19, 2025· Updated Jun 17, 2026

CVE-2025-66493

CVE-2025-66493

Description

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1

on Windows

. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.1.23955
    • (no CPE)range: <2025.2.1, <14.0.1, <13.2.1
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*range: <=2025.2.1.33197
    • (no CPE)range: <2025.2.1, <14.0.1, <13.2.1
  • Foxit Software Inc./Foxit PDF Editorv5
    Range: Versions 2025.2.1 and earlier
  • Foxit Software Inc./Foxit PDF Readerv5
    Range: Versions 2025.2.1 and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.