ZDI-CAN-28531: ZDI-25-1178: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2025-66497.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28531?
The severity of ZDI-CAN-28531 is determined by its CVSS score, which reflects the potential impact of remote attackers disclosing sensitive information.
How do I fix ZDI-CAN-28531?
To fix ZDI-CAN-28531, update your Foxit PDF Reader to the latest version provided by the vendor.
What type of vulnerability is ZDI-CAN-28531?
ZDI-CAN-28531 is a remote information disclosure vulnerability requiring user interaction to be exploited.
What software is affected by ZDI-CAN-28531?
ZDI-CAN-28531 affects installations of Foxit PDF Reader.
Can ZDI-CAN-28531 be exploited remotely?
Yes, ZDI-CAN-28531 can be exploited remotely, but it requires user interaction such as visiting a malicious page or opening a malicious file.