VYPR
High severity7.8NVD Advisory· Published Dec 19, 2025· Updated Jun 17, 2026

CVE-2025-66494

CVE-2025-66494

Description

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
    Range: <=13.2.1.23955
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*range: <=2025.2.1.33197
    • (no CPE)range: <2025.2.1, <14.0.1, <13.2.1
  • Foxit Software Inc./Foxit PDF Editorv5
    Range: Versions 2025.2.1 and earlier
  • Foxit Software Inc./Foxit PDF Readerv5
    Range: Versions 2025.2.1 and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.