Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-69627

29
FAUCET Score

OVERVIEW CVE-2025-69627 is a heap use-after-free vulnerability affecting Nitro PDF Pro for Windows version 14.41.1.4. The flaw exists in the JavaScript implementation of the mailDoc() method, where an internal XID object is prematurely freed but subsequently passed to UI and logging helper functions, potentially exposing freed memory containing unpredictable heap data or attacker-controlled strings. SEVERITY This vulnerability carries a CVSS score of 8.4 (High) with a local attack vector requiring no user interaction or privileges. The low complexity of exploitation combined with high potential impact across confidentiality, integrity, and availability makes this a significant risk. Exploitation can result in access violations and non-deterministic crashes through invalid or stale pointer processing in downstream functions such as wcscmp(). EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no publicly available exploit code has been reported. Community attention remains minimal, with an EPSS score of 0.000070 indicating extremely low probability of exploitation compared to the broader CVE population. Organizations should nevertheless prioritize patching given the severity rating and the potential for weaponization.

Impacted Technologies

VendorProductVersion(s)CPE
14.41.1.4CPE matchmatch criteria
cpe:2.3:a:gonitro:nitro_pdf_pro:14.41.1.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 14th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

jeroscope.com / advisories/2025/jero-2025-016
Third Party Advisory