CVE-2025-66498: Foxit PDF Reader 3D Annotation Out-of-Bounds Memory Access Vulnerability
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66498?
CVE-2025-66498 is considered a critical vulnerability due to its potential for memory corruption and possible exploitation.
How do I fix CVE-2025-66498?
To address CVE-2025-66498, ensure that you update to the latest version of Foxit PDF Reader that includes patches for this vulnerability.
What types of attacks can be launched using CVE-2025-66498?
An attacker may exploit CVE-2025-66498 by crafting a malicious PDF file that triggers out-of-bounds memory access in Foxit PDF Reader.
What software versions are affected by CVE-2025-66498?
CVE-2025-66498 affects all versions of Foxit PDF Reader prior to the release that includes the relevant security patches.
What are the risks associated with CVE-2025-66498?
The risks of CVE-2025-66498 include potential execution of arbitrary code, system crashes, and data breaches.