8.8
CVSSv3

CVE-2025-0909

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00054 | KEV: Not Included
Published: 11/02/2025 Updated: 12/02/2025

Vulnerability Summary

Information Disclosure Vulnerability in PDF-XChange Editor XPS File Parsing

PDF-XChange Editor contains a vulnerability in XPS file parsing that allows remote attackers to disclose sensitive information. An attacker can trick a user into visiting a malicious page or opening a malicious file to trigger the information disclosure. The vulnerability stems from improper validation during XPS file parsing, which can cause a read beyond the allocated memory object. An attacker could potentially combine this flaw with other vulnerabilities to execute code in the current process context. This security issue was tracked as ZDI-CAN-25678 and requires user interaction to be successfully exploited.

Vulnerable Product Search on Vulmon Subscribe to Product

pdf-xchange pdf-xchange editor