CVE-2025-55307: Low severity Foxit Foxit PDF and Editor for Windows vulnerability
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55307?
CVE-2025-55307 has been classified as a high-severity vulnerability due to its potential to cause an out-of-bounds read.
How do I fix CVE-2025-55307?
To fix CVE-2025-55307, you should update Foxit PDF and Editor for Windows to version 13.2 or later, or 2025.2 or later.
What software is affected by CVE-2025-55307?
CVE-2025-55307 affects Foxit PDF and Editor for Windows versions before 13.2 and 2025 versions before 2025.2.
What type of attack does CVE-2025-55307 enable?
CVE-2025-55307 enables attackers to exploit a crafted PDF to cause an out-of-bounds read, potentially leading to information disclosure.
Is there a workaround for CVE-2025-55307?
Currently, there are no known workarounds for CVE-2025-55307 other than updating to a patched version.