CVE-2025-0904
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-0904 is an Information Disclosure vulnerability in PDF-XChange Editor's XPS File parsing feature. This issue stems from insufficient validation of user-supplied data, enabling remote attackers to read beyond the allocated memory. The exploitation of this vulnerability necessitates user interaction, either through visiting malicious websites or opening tainted files. By exploiting this flaw, attackers can potentially gain sensitive information, which, when combined with other vulnerabilities, could lead to arbitrary code execution within the affected system. (ZDI-CAN-25422)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PDF-XChange Editor