CVE-2025-55312: Null Pointer Dereference
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55312?
CVE-2025-55312 is classified as a high severity vulnerability due to its impact on the application's internal state management.
How do I fix CVE-2025-55312?
To fix CVE-2025-55312, update Foxit PDF and Editor to version 13.2 or later for Windows and 2025.2 or later for the 2025 version.
What are the potential consequences of CVE-2025-55312?
The potential consequences of CVE-2025-55312 include crashes and unintended behavior in PDF annotation management operations.
Which versions are affected by CVE-2025-55312?
CVE-2025-55312 affects Foxit PDF and Editor for Windows versions prior to 13.2 and Foxit PDF and Editor 2025 prior to 2025.2.
Is CVE-2025-55312 applicable to Mac or Linux versions?
CVE-2025-55312 is not applicable to Mac or Linux versions, as it specifically affects Windows versions of Foxit PDF and Editor.