CVE-2025-66494: Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability
A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66494?
CVE-2025-66494 is classified as a critical use-after-free vulnerability that could allow remote code execution.
How do I fix CVE-2025-66494?
To fix CVE-2025-66494, update to Foxit PDF Reader version 2025.2.1, 14.0.1, or 13.2.1 or later.
What causes the CVE-2025-66494 vulnerability?
CVE-2025-66494 is caused by a PDF object being freed while still referenced by multiple parent objects.
Which versions of Foxit PDF Reader are affected by CVE-2025-66494?
Foxit PDF Reader versions prior to 2025.2.1, 14.0.1, and 13.2.1 on Windows are affected by CVE-2025-66494.
Can CVE-2025-66494 be exploited remotely?
Yes, CVE-2025-66494 can potentially be exploited by remote attackers to execute arbitrary code.