CVE-2025-55308: Use After Free
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55308?
CVE-2025-55308 is classified as a use-after-free vulnerability, which can lead to memory corruption issues.
How do I fix CVE-2025-55308?
To mitigate CVE-2025-55308, update Foxit PDF and Editor for Windows to version 13.2 or later, or to version 2025.2 or later.
What types of software are affected by CVE-2025-55308?
CVE-2025-55308 affects Foxit PDF and Editor for Windows prior to version 13.2 and Foxit PDF and Editor prior to version 2025.2.
What are the potential impacts of CVE-2025-55308?
The potential impacts of CVE-2025-55308 include memory corruption which may lead to application crashes or exploitation by attackers.
Is CVE-2025-55308 related to JavaScript in PDF files?
Yes, CVE-2025-55308 arises from a crafted PDF that uses JavaScript to call closeDoc() prematurely.