Download of code without integrity check in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2025-55310
Published: August 13, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to software does not perform software integrity check when downloading updates. A local user can place a malicious file on the system and the application will load it without performing an integrity check, leading to code execution.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2025-55310
Foxit PDF Reader for Windows - update to 2025.2.0.33046