CVE-2025-66493: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1
on Windows
. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66493?
CVE-2025-66493 has been classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
What products are affected by CVE-2025-66493?
CVE-2025-66493 affects Foxit PDF Reader and Foxit PDF Editor versions prior to 2025.2.1.
How do I fix CVE-2025-66493?
To fix CVE-2025-66493, you should update Foxit PDF Reader and Foxit PDF Editor to version 2025.2.1 or later.
What type of vulnerability is CVE-2025-66493?
CVE-2025-66493 is a use-after-free vulnerability that can be exploited through specially crafted PDF files.
Can CVE-2025-66493 lead to data compromise?
Yes, CVE-2025-66493 can potentially lead to data compromise as it allows attackers to execute arbitrary code.