An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
History

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Foxit
Foxit pdf Editor
Foxit pdf Editor For Mac
Microsoft
Microsoft windows
Vendors & Products Apple
Apple macos
Foxit
Foxit pdf Editor
Foxit pdf Editor For Mac
Microsoft
Microsoft windows

Thu, 11 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-11T00:00:00.000Z

Updated: 2025-12-11T15:56:50.547Z

Reserved: 2025-08-12T00:00:00.000Z

Link: CVE-2025-55313

cve-icon Vulnrichment

Updated: 2025-12-11T15:56:44.185Z

cve-icon NVD

Status : Received

Published: 2025-12-11T16:16:25.780

Modified: 2025-12-11T16:16:25.780

Link: CVE-2025-55313

cve-icon Redhat

No data.