CVE-2025-9327 Overview
CVE-2025-9327 is an out-of-bounds read vulnerability in Foxit PDF Reader and Foxit PDF Editor. The flaw resides in the parser for PRC (Product Representation Compact) files embedded within PDF documents. Attackers can leverage this issue to disclose sensitive process memory on affected Windows installations. Exploitation requires user interaction: the victim must open a malicious PDF or visit a page that serves one. The Zero Day Initiative tracks this issue as ZDI-CAN-26774 and published advisory ZDI-25-865. Foxit has issued a security bulletin covering the affected releases.
Critical Impact
An attacker can read beyond an allocated buffer to leak memory contents and chain the primitive with other bugs to achieve arbitrary code execution in the context of the current user.
Affected Products
- Foxit PDF Reader on Microsoft Windows
- Foxit PDF Editor (including build 2025.1.0.27937) on Microsoft Windows
- Microsoft Windows host platform
Discovery Timeline
- 2025-09-02 - CVE-2025-9327 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9327
Vulnerability Analysis
The vulnerability lives in the routine that parses PRC file streams embedded within PDF documents. PRC is a 3D data format supported by Foxit's rendering pipeline for interactive product representations. The parser fails to properly validate size or offset fields drawn from attacker-controlled input. As a result, the code reads past the end of a heap-allocated buffer during PRC deserialization. Leaked bytes can include heap metadata, object pointers, and other in-process data useful for defeating Address Space Layout Randomization (ASLR). Foxit's security bulletin lists the fixed versions for both PDF Reader and PDF Editor.
Root Cause
The root cause is an out-of-bounds read classified under [CWE-125]. The PRC parser trusts a length or index field from the file without bounds-checking it against the allocated buffer, so the read walks off the end of the object.
Attack Vector
Exploitation is local and requires user interaction. A victim must open a crafted PDF in Foxit PDF Reader or Editor, or open a malicious page that streams the document into the reader. Because the primitive discloses memory rather than corrupting it, adversaries typically combine CVE-2025-9327 with a second memory-corruption bug to bypass ASLR and reach arbitrary code execution in the user's context. See the ZDI Advisory ZDI-25-865 for the technical background.
Detection Methods for CVE-2025-9327
Indicators of Compromise
- PDF files containing embedded PRC (3D annotation) streams delivered by email, chat, or drive-by download
- Foxit Reader or Editor processes spawning unexpected child processes such as cmd.exe, powershell.exe, or scripting hosts shortly after opening a PDF
- Crash artifacts or Windows Error Reporting entries for FoxitPDFReader.exe or FoxitPDFEditor.exe referencing the PRC handler
Detection Strategies
- Inspect inbound PDFs for the /3D annotation subtype and PRC stream markers using content-disarm-and-reconstruction or sandbox detonation
- Monitor endpoint telemetry for anomalous memory reads, access violations, or module loads originating from Foxit processes
- Alert on Foxit processes making outbound network connections immediately after document open, which may indicate second-stage payload retrieval
Monitoring Recommendations
- Track installed Foxit PDF Reader and PDF Editor versions across the estate and flag builds at or below 2025.1.0.27937
- Ingest Windows process, file, and network telemetry into a centralized analytics platform so PDF-borne exploitation chains are reconstructable
- Review the Foxit Security Bulletins page regularly for related PRC parser advisories
How to Mitigate CVE-2025-9327
Immediate Actions Required
- Update Foxit PDF Reader and Foxit PDF Editor to the fixed release identified in the Foxit Security Bulletins
- Restrict opening of PDFs from untrusted senders and enable enterprise attachment sandboxing at the mail gateway
- Deliver user awareness reminders that unsolicited PDFs, especially those with 3D or CAD content, should be treated as suspicious
Patch Information
Foxit has released fixed builds of PDF Reader and PDF Editor addressing the PRC parser flaw. Refer to the vendor's Foxit Security Bulletins for the exact patched version numbers and the ZDI Advisory ZDI-25-865 for coordinated disclosure details. Deploy the update through your standard software distribution channel and validate the version on endpoints post-deployment.
Workarounds
- Disable 3D content rendering in Foxit preferences to block the vulnerable PRC parsing path
- Configure enterprise policy to open PDFs in Protected Mode or Safe Reading Mode until patches are deployed
- Route inbound PDFs through a sandbox or content-disarm-and-reconstruction service that strips embedded 3D annotations
# Configuration example: query installed Foxit versions on Windows endpoints
Get-ItemProperty "HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*" |
Where-Object { $_.DisplayName -like "Foxit PDF*" } |
Select-Object DisplayName, DisplayVersion, InstallLocation
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
