TROYANOSYVIRUS
Back to CVEs

CVE-2025-66497

MEDIUM
5.3

Description

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

CVE Details

CVSS v3.1 Score5.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published12/19/2025
Last Modified12/23/2025
Sourcenvd
Honeypot Sightings0

Affected Products

apple:macosfoxit:pdf_editorfoxit:pdf_readermicrosoft:windows

Weaknesses (CWE)

CWE-125CWE-787

References

https://www.foxit.com/support/security-bulletins.html(14984358-7092-470d-8f34-ade47a7658a2)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.