« Volver al listado

CVE-2025-66495

Estado: AnalizadaAlta (7.8)—

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R + CWE-416 (use-after-free) en manejador de anotaciones JavaScript de PDF indica ejecución en cliente mediante archivo preparado. Permite ejecutar código arbitrario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-66495",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-66495",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-19T14:45:11.448267Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "14984358-7092-470d-8f34-ade47a7658a2",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "14984358-7092-470d-8f34-ade47a7658a2",
      "affectedData": [
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Reader",
          "versions": [
            {
              "status": "affected",
              "version": "Versions 2025.2.1 and earlier"
            },
            {
              "status": "affected",
              "version": "Versions 14.0.1 and earlier"
            },
            {
              "status": "affected",
              "version": "Versions 13.2.1 and eariler"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Editor",
          "versions": [
            {
              "status": "affected",
              "version": "Versions 2025.2.1 and earlier"
            },
            {
              "status": "affected",
              "version": "Versions 14.0.1 and earlier"
            },
            {
              "status": "affected",
              "version": "Versions 13.2.1 and eariler"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-19T07:16:02.380",
  "references": [
    {
      "url": "https://www.foxit.com/support/security-bulletins.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "14984358-7092-470d-8f34-ade47a7658a2"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "14984358-7092-470d-8f34-ade47a7658a2",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code."
    }
  ],
  "lastModified": "2026-06-17T09:56:56.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAE67A0F-4DFE-4268-90D5-789CCA2155A6",
              "versionEndIncluding": "13.2.1.23955"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1694C31-1717-40B3-9E11-773E39F288A8",
              "versionEndIncluding": "14.0.1.33197",
              "versionStartIncluding": "14.0.0.33046"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C75FEE6-54F3-49C6-BAEA-A09D23BE5D64",
              "versionEndIncluding": "2023.3.0.23028",
              "versionStartIncluding": "2023.1.0.15510"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C06BC41-9831-4AE3-B10B-3FC313D01580",
              "versionEndIncluding": "2024.4.1.27687",
              "versionStartIncluding": "2024.1.0.23997"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AC7F7F1-B05D-48C7-9DD3-CFC7CBA2E275",
              "versionEndIncluding": "2025.2.1.33197",
              "versionStartIncluding": "2025.1.0.27937"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "538915D1-1531-44A8-B15D-BCFE1356BCB5",
              "versionEndIncluding": "2025.2.1.33197"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF36C22F-253D-4ACE-A202-1BC66099FB43",
              "versionEndIncluding": "13.2.1.63315"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EAD777E-152E-4870-8CFD-10A4ED542409",
              "versionEndIncluding": "14.0.1.69005",
              "versionStartIncluding": "14.0.0.33046"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D41C109-FCCC-467D-AC01-37CE4106DC89",
              "versionEndIncluding": "2023.3.0.63083",
              "versionStartIncluding": "2023.1.0.15510"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5CE4481-BEBB-4646-B235-DCE82AEBD265",
              "versionEndIncluding": "2024.4.1.66479",
              "versionStartIncluding": "2024.1.0.23997"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0778A96-55FD-452C-88F5-EE42D2D8CE49",
              "versionEndIncluding": "2025.2.1.69005",
              "versionStartIncluding": "2025.1.0.27937"
            },
            {
              "criteria": "cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83D931C5-F081-441F-8B29-4FDD7B32327A",
              "versionEndIncluding": "2025.2.1.69005"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "14984358-7092-470d-8f34-ade47a7658a2"
}