CVE-2025-0906
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-0906 is an Information Disclosure vulnerability in PDF-XChange Editor. This issue arises due to an Out-of-Bounds Read flaw during JB2 file parsing. Attackers can exploit this vulnerability by persuading users to visit a malicious webpage or open a specially crafted file. The flaw stems from inadequate validation of user-supplied data, enabling read access beyond the allocated buffer. While this vulnerability does not directly lead to code execution, it can be combined with other weaknesses for more severe attacks. ZDI-CAN-25434 first disclosed this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PDF-XChange Editor