{"id":9115,"date":"2025-12-11T10:03:37","date_gmt":"2025-12-11T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/11\/adobe-acrobat-reader-vulnerabilities-let-attackers-execute-arbitrary-code-and-bypass-security\/"},"modified":"2025-12-11T10:03:37","modified_gmt":"2025-12-11T10:03:37","slug":"adobe-acrobat-reader-vulnerabilities-let-attackers-execute-arbitrary-code-and-bypass-security","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/11\/adobe-acrobat-reader-vulnerabilities-let-attackers-execute-arbitrary-code-and-bypass-security\/","title":{"rendered":"Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security"},"content":{"rendered":"<p>    Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute\u00a0<a href=\"https:\/\/cybersecuritynews.com\/picklescan-0-day-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">arbitrary code<\/a>\u00a0and bypass essential security features.<\/span><\/p>\n<p>Adobe issued security bulletin APSB25-119 on December 9, 2025, with a priority rating of 3, affecting both Windows and <a href=\"https:\/\/cybersecuritynews.com\/zoom-rooms-for-windows-and-macos\/\" target=\"_blank\" rel=\"noreferrer noopener\">macOS<\/a> platforms. The vulnerabilities stem from multiple weaknesses in the PDF processing engine.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Vulnerability<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Category<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Impact<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Severity<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS Score<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Untrusted Search Path<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-426<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Arbitrary code execution<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">7.8<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64785<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Out-of-bounds Read<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-125<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Arbitrary code execution<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">7.8<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64899<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Improper Verification of Cryptographic Signature<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-347<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Security feature bypass<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Moderate<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">3.3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64786<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Improper Verification of Cryptographic Signature<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-347<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Security feature bypass<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Moderate<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">3.3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64787<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-how-attackers-could-exploit-the-flaws\"><strong>How Attackers Could Exploit the Flaws<\/strong><\/h2>\n<p>Two critical flaws enable arbitrary code execution through untrusted search path vulnerabilities and <a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">out-of-bounds<\/a> read errors. These issues carry a CVSS base score of 7.8, indicating severe risk to users.<\/p>\n<p>Two additional moderate vulnerabilities related to improper verification of cryptographic signatures could allow attackers to bypass security features, each with a CVSS score of 3.3.<\/p>\n<p>The affected products include Acrobat DC, Acrobat Reader DC, Acrobat 2024, Acrobat 2020, and Acrobat Reader 2020 across all current versions.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Product<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Track<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected Versions<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Platform<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Acrobat DC<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Continuous<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">25.001.20982 and earlier<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows &amp; macOS<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Acrobat Reader DC<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Continuous<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">25.001.20982 and earlier<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows &amp; macOS<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Acrobat 2024<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Classic 2024<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Win \u2013 24.001.30264 and earlier; Mac \u2013 24.001.30273 and earlier<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows &amp; macOS<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Acrobat 2020<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Classic 2020<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Win \u2013 20.005.30793 and earlier; Mac \u2013 20.005.30803 and earlier<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows &amp; macOS<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Acrobat Reader 2020<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Classic 2020<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Win \u2013 20.005.30793 and earlier; Mac \u2013 20.005.30803 and earlier<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows &amp; macOS<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Adobe <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb25-119.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">recommends<\/a> installing the latest versions immediately. Users can update manually through Help &gt; Check for Updates, or allow automatic updates to install security patches without intervention.<\/p>\n<p>The updated versions include Acrobat DC and Reader DC 25.001.20997, Acrobat 2024 versions 24.001.30307 (Windows) and 24.001.30308 (macOS), and Acrobat 2020 versions 20.005.30838 across both platforms.<\/p>\n<p>IT administrators should deploy updates <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">using their preferred method, such as AIP-GPO,\u00a0<a href=\"https:\/\/cybersecuritynews.com\/adobe-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noopener\">bootstrapper<\/a>, or SCCM,<\/span> for Windows environments.<\/p>\n<p>Currently, Adobe reports no known exploits targeting these vulnerabilities in the wild. However, the critical nature of the flaws and their potential for remote execution make <a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-patching\/\" target=\"_blank\" rel=\"noreferrer noopener\">prompt patching<\/a> essential.<\/p>\n<p>Organizations should prioritize updating all affected Acrobat installations to prevent potential compromise.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/adobe-acrobat-reader-vulnerabilities-code\/\">Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/adobe-acrobat-reader-vulnerabilities-code\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute\u00a0arbitrary code\u00a0and bypass essential security features. Adobe issued security bulletin APSB25-119 on December 9, 2025, with a priority rating of 3, affecting both Windows and macOS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2015,129,63,648],"tags":[130],"class_list":["post-9115","post","type-post","status-publish","format-standard","hentry","category-cve-vulnerabilities","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9115"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9115"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9115\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}