TROYANOSYVIRUS
Volver a CVEs

CVE-2025-66498

MEDIUM
5.3

Descripcion

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

Detalles CVE

Puntuacion CVSS v3.15.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado12/19/2025
Ultima modificacion12/23/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

foxit:pdf_editorfoxit:pdf_readermicrosoft:windows

Debilidades (CWE)

CWE-125CWE-787

Referencias

https://www.foxit.com/support/security-bulletins.html(14984358-7092-470d-8f34-ade47a7658a2)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.