CVE-2025-0904

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 12, 2025
CWE ID 125

Summary

CVE-2025-0904 is an Information Disclosure vulnerability in PDF-XChange Editor's XPS File parsing feature. This issue stems from insufficient validation of user-supplied data, enabling remote attackers to read beyond the allocated memory. The exploitation of this vulnerability necessitates user interaction, either through visiting malicious websites or opening tainted files. By exploiting this flaw, attackers can potentially gain sensitive information, which, when combined with other vulnerabilities, could lead to arbitrary code execution within the affected system. (ZDI-CAN-25422)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share