OVERVIEW CVE-2025-69627 is a heap use-after-free vulnerability affecting Nitro PDF Pro for Windows version 14.41.1.4. The flaw exists in the JavaScript implementation of the mailDoc() method, where an internal XID object is prematurely freed but subsequently passed to UI and logging helper functions, potentially exposing freed memory containing unpredictable heap data or attacker-controlled strings. SEVERITY This vulnerability carries a CVSS score of 8.4 (High) with a local attack vector requiring no user interaction or privileges. The low complexity of exploitation combined with high potential impact across confidentiality, integrity, and availability makes this a significant risk. Exploitation can result in access violations and non-deterministic crashes through invalid or stale pointer processing in downstream functions such as wcscmp(). EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no publicly available exploit code has been reported. Community attention remains minimal, with an EPSS score of 0.000070 indicating extremely low probability of exploitation compared to the broader CVE population. Organizations should nevertheless prioritize patching given the severity rating and the potential for weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.41.1.4CPE matchmatch criteria | cpe:2.3:a:gonitro:nitro_pdf_pro:14.41.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.