Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security
Adobe has released critical security updates for Acrobat and Reader, addressing vulnerabilities that allow attackers to execute arbitrary code and bypass security features. These updates are identified in security bulletin APSB25-119, issued on Tue, Dec…
Adobe has released critical security updates for Acrobat and Reader, addressing vulnerabilities that allow attackers to execute arbitrary code and bypass security features. These updates are identified in security bulletin APSB25-119, issued on Tue, Dec 9, 2025, and apply to both Windows and macOS platforms. The vulnerabilities originate from weaknesses in the PDF processing engine.
Vulnerability Category Impact Severity CVSS Score CVE
Untrusted Search Path CWE-426 Arbitrary code execution Critical 7.8 CVE-2025-64785
Out-of-bounds Read CWE-125 Arbitrary code execution Critical 7.8 CVE-2025-64899
Improper Verification of Cryptographic Signature CWE-347 Security feature bypass Moderate 3.3 CVE-2025-64786
Improper Verification of Cryptographic Signature CWE-347 Security feature bypass Moderate 3.3 CVE-2025-64787
The critical vulnerabilities involve arbitrary code execution through untrusted search path and out-of-bounds read errors, both carrying a CVSS base score of 7.8. Two moderate vulnerabilities related to cryptographic signature verification could permit security feature bypass, each with a CVSS score of 3.3.
These updates are identified in security bulletin APSB25-119, issued on Tue, Dec 9, 2025, and apply to both Windows and macOS platforms.
The following products are impacted across all current versions:
Product Track Affected Versions Platform
Acrobat DC Continuous 25.001.20982 and earlier Windows & macOS
Acrobat Reader DC Continuous 25.001.20982 and earlier Windows & macOS
Acrobat 2024 Classic 2024 Win – 24.001.30264 and earlier; Mac – 24.001.30273 and earlier Windows & macOS
Acrobat 2020 Classic 2020 Win – 20.005.30793 and earlier; Mac – 20.005.30803 and earlier Windows & macOS
Acrobat Reader 2020 Classic 2020 Win – 20.005.30793 and earlier; Mac – 20.005.30803 and earlier Windows & macOS
Adobe advises users to install the latest versions immediately. Updates can be accessed manually via Help > Check for Updates, or through automatic updates. The new versions include Acrobat DC and Reader DC 25.001.20997, Acrobat 2024 versions 24.001.30307 (Windows) and 24.001.30308 (macOS), and Acrobat 2020 versions 20.005.30838 for both platforms.
IT administrators are encouraged to deploy updates using methods such as AIP-GPO, bootstrapper, or SCCM in Windows environments. Although no exploits have been reported in the wild, the critical nature of these vulnerabilities requires prompt patching to mitigate risks.
Organizations should prioritize updating all affected installations to ensure security and prevent potential breaches.
Based on reporting by Cyber Security News.
