CVE-2025-55313: Code Injection
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55313?
CVE-2025-55313 has been rated as critical due to the potential for arbitrary code execution.
How do I fix CVE-2025-55313?
To mitigate CVE-2025-55313, update Foxit PDF and Editor to the latest version above 13.2 or 2025.2.
What causes CVE-2025-55313?
CVE-2025-55313 is caused by insufficient handling of memory allocation failures when processing specially crafted PDF files.
Which versions are affected by CVE-2025-55313?
CVE-2025-55313 affects Foxit PDF and Editor versions prior to 13.2 and 2025 before 2025.2.
Is CVE-2025-55313 under active exploitation?
As of now, there are no confirmed reports of active exploitation of CVE-2025-55313 in the wild.