CVE-2025-55308

CWE-416Use After Free4 documents4 sources
Severity
6.7MEDIUM
EPSS
0.0%
top 97.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11

Description

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDfoxit/pdf_editor2023.1.0.155102023.3.0.23028+3
NVDfoxit/pdf_reader2025.1.0.27937

🔴Vulnerability Details

2
CVEList
CVE-2025-55308: An issue was discovered in Foxit PDF and Editor for Windows before 132025-12-11
GHSA
GHSA-9rvx-wgxm-jc7g: An issue was discovered in Foxit PDF and Editor for Windows before 132025-12-11

🕵️Threat Intelligence

1
Wiz
CVE-2025-55308 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-55308 (MEDIUM CVSS 6.7) | An issue was discovered in Foxit PD | cvebase.io