ZDI-25-1179: Foxit PDF Reader U3D File Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2025-66498.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1179?
The severity of ZDI-25-1179 is assessed as moderate due to the requirement for user interaction to exploit the vulnerability.
How do I fix ZDI-25-1179?
To fix ZDI-25-1179, update Foxit PDF Reader to the latest version provided by the vendor.
What type of vulnerability is identified as ZDI-25-1179?
ZDI-25-1179 is a remote information disclosure vulnerability affecting Foxit PDF Reader.
Who is affected by ZDI-25-1179?
Users of Foxit PDF Reader are affected by ZDI-25-1179 if they interact with malicious pages or files.
Is user interaction needed to exploit ZDI-25-1179?
Yes, user interaction is required for exploiting ZDI-25-1179.