CVE-2025-66769

A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:gonitro:nitro_pdf_pro:14.41.1.4:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Apr 2026, 16:51

Type Values Removed Values Added
First Time Microsoft
Gonitro
Gonitro nitro Pdf Pro
Microsoft windows
CPE cpe:2.3:a:gonitro:nitro_pdf_pro:14.41.1.4:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://jeroscope.com/advisories/2025/jero-2025-015/ - () https://jeroscope.com/advisories/2025/jero-2025-015/ - Third Party Advisory
References () https://www.gonitro.com/ - () https://www.gonitro.com/ - Product

13 Apr 2026, 20:16

Type Values Removed Values Added
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

13 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 16:16

Updated : 2026-04-23 16:51


NVD link : CVE-2025-66769

Mitre link : CVE-2025-66769

CVE.ORG link : CVE-2025-66769


JSON object : View

Products Affected

microsoft

  • windows

gonitro

  • nitro_pdf_pro
CWE
CWE-476

NULL Pointer Dereference