CVE-2025-66499: Foxit PDF Reader PDF Parsing Heap-Based Buffer Overflow Remote Code Execution Vulnerability
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66499?
CVE-2025-66499 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2025-66499?
To mitigate CVE-2025-66499, ensure you update Foxit PDF Reader to the latest version provided by Foxit.
What are the risks associated with CVE-2025-66499?
The risks include the possibility of remote attackers executing arbitrary code on affected systems.
Which versions of Foxit PDF Reader are affected by CVE-2025-66499?
All versions of Foxit PDF Reader that have not been patched are vulnerable to CVE-2025-66499.
Is CVE-2025-66499 being actively exploited?
While there is no public indication of active exploitation for CVE-2025-66499, it is advisable to apply patches immediately.