Skip to main content

CVE-2025-9324: Foxit PDF Editor Information Disclosure Flaw

CVE-2025-9324 is an out-of-bounds read flaw in Foxit PDF Editor that enables attackers to disclose sensitive information through malicious PRC files. This post explains its technical details, affected versions, and mitigation.

Published:

CVE-2025-9324 Overview

CVE-2025-9324 is an out-of-bounds read vulnerability [CWE-125] in Foxit PDF Reader and Foxit PDF Editor. The flaw exists in the parser that handles Product Representation Compact (PRC) files embedded within PDF documents. Attackers can leverage the read primitive to disclose memory contents from the application process. Exploitation requires user interaction: the victim must open a crafted PDF or visit a malicious page that loads one. The issue was reported through Trend Micro's Zero Day Initiative under identifier ZDI-CAN-26802.

Critical Impact

Attackers can leak sensitive process memory and chain the read primitive with other flaws to achieve arbitrary code execution in the context of the current user.

Affected Products

  • Foxit PDF Reader (Windows and macOS)
  • Foxit PDF Editor 2025.1.0.27937 and prior
  • Foxit PDF Editor 2025.1.0.66692 and prior

Discovery Timeline

  • 2025-09-02 - CVE-2025-9324 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9324

Vulnerability Analysis

The vulnerability resides in Foxit's PRC file parser. PRC is a 3D data format used to embed CAD-style geometry inside PDF documents. The parser reads structured records from the PRC stream without adequately validating length fields and offsets supplied by the file. When the parser accesses data beyond the bounds of an allocated buffer, it returns adjacent heap memory to the calling routine.

An attacker who controls the PRC stream can shape the read to return process memory that would otherwise be inaccessible. Disclosed bytes may include heap metadata, pointers, and object contents useful for defeating Address Space Layout Randomization (ASLR). Trend Micro's Zero Day Initiative notes the primitive can be combined with other Foxit vulnerabilities to achieve arbitrary code execution.

Root Cause

The defect is a classic missing-bounds-check pattern in native C or C++ parsing code. User-supplied size or index values from the PRC stream are trusted and applied directly to buffer accesses. The parser does not verify that the resulting read remains within the allocated object, satisfying the definition of [CWE-125] Out-of-Bounds Read.

Attack Vector

Exploitation is local and requires user interaction. A target must open a malicious PDF containing a crafted PRC stream in Foxit PDF Reader or Foxit PDF Editor. Delivery vectors include email attachments, drive-by downloads, and links opened in a browser configured with the Foxit browser plugin. No authentication is required. See the Zero Day Initiative Advisory ZDI-25-868 for the vendor-coordinated disclosure record.

No verified public exploit code is available for this issue at time of writing.

Detection Methods for CVE-2025-9324

Indicators of Compromise

  • PDF files containing embedded 3D PRC streams with malformed length or offset fields.
  • Foxit PDF Reader or Foxit PDF Editor process crashes with access violations while rendering 3D content.
  • Unexpected child processes spawned by FoxitPDFReader.exe or FoxitPDFEditor.exe shortly after opening a document.

Detection Strategies

  • Deploy YARA rules that flag PDF objects with /Subtype /PRC or /3D annotations paired with anomalous stream sizes.
  • Correlate document-open telemetry with process-crash events on the endpoint to identify targeted delivery attempts.
  • Inspect email gateway attachments for PDFs containing 3D annotations sourced from untrusted senders.

Monitoring Recommendations

  • Track installed Foxit versions across managed endpoints and alert on hosts running vulnerable builds.
  • Monitor for outbound network activity from Foxit processes immediately following document rendering.
  • Log Windows Error Reporting and macOS crash reports referencing Foxit modules for retrospective hunting.

How to Mitigate CVE-2025-9324

Immediate Actions Required

  • Update Foxit PDF Reader and Foxit PDF Editor to the fixed builds identified in the vendor security bulletin.
  • Restrict opening of untrusted PDF attachments until affected endpoints are patched.
  • Disable the Foxit browser plugin on systems where PDFs are commonly opened from the web.

Patch Information

Foxit has published fixed releases through its security advisory portal. Refer to the Foxit Security Bulletins for the exact patched build numbers for both Windows and macOS, and roll out updates through your standard patch management workflow.

Workarounds

  • Disable 3D content rendering in Foxit preferences under File > Preferences > 3D to block PRC parsing.
  • Enable Safe Reading Mode in Foxit to limit execution of embedded content in untrusted documents.
  • Route inbound PDFs through a sandboxed rendering service or content disarm and reconstruction (CDR) gateway.
bash
# Windows registry example: disable 3D content in Foxit PDF Reader
reg add "HKCU\Software\Foxit Software\Foxit PDF Reader\Preferences\3D" /v "bEnable3D" /t REG_DWORD /d 0 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.