CVE-2025-66769 is a NULL pointer dereference vulnerability in Nitro PDF Pro for Windows version 14.41.1.4 that enables remote attackers to trigger a denial of service condition through specially crafted XFA packets. The vulnerability has a CVSS v3.1 severity rating of 7.5 (HIGH) and requires no user authentication or interaction, making it easily exploitable over the network. The attack vector is network-based with low complexity, though the impact is limited to availability disruption without compromising confidentiality or integrity. Currently, this vulnerability shows minimal exploitation activity with no public exploit code available and an exceptionally low EPSS score of 0.00017, indicating it ranks below typical CVE activity levels. The vulnerability remains on inactive status with no evidence of active exploitation in the wild, suggesting organizations can prioritize patching based on their Nitro PDF Pro usage levels rather than immediate threat response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.41.1.4CPE matchmatch criteria | cpe:2.3:a:gonitro:nitro_pdf_pro:14.41.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.