CVE-2025-55313 is a high-severity arbitrary code execution vulnerability affecting Foxit PDF and Editor for Windows and macOS versions prior to 13.2 and 2025.2, respectively. The flaw arises from improper handling of memory allocation failures when processing crafted PDF files, specifically when an extremely large value is assigned to a form field's charLimit property via JavaScript. This can lead to memory corruption, allowing an attacker to execute arbitrary code if a user opens a malicious PDF. The vulnerability has a CVSS score of 7.8 (High) and requires user interaction (UI:R) to exploit, but has low attack complexity (AC:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2023.1.0.15510, <= 2023.3.0.23028CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2024.1.0.23997, <= 2024.4.1.27687CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
2025.1.0.27937CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:2025.1.0.27937:*:*:*:*:*:*:* | ||
<= 2025.1.0.27937CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* | ||
<= 13.1.7.63027CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.