CVE-2025-0900
CVSS 3.0 Score 3.3 of 10 (low)
Details
Summary
CVE-2025-0900 is an Information Disclosure vulnerability affecting PDF-XChange Editor. This issue stems from an out-of-bounds read in PDF file parsing, which allows remote attackers to disclose sensitive information. The flaw arises due to insufficient validation of user-supplied data, enabling reading past the end of an allocated object. While this vulnerability does not result in code execution directly, it can be exploited in conjunction with other vulnerabilities, potentially leading to arbitrary code execution. The ZDI identified this issue as ZDI-CAN-25368.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.