Ad

CVE-2025-54257

HIGH CVSS 3.1: 7.8 EPSS 0.04%
Updated Nov 03, 2025
Apple
Parameter Value
CVSS 7.8 (HIGH)
Affected Versions 15.008.20082 — 25.001.20693
Fixed In 24.001.30264
Type CWE-416 (Use After Free)
Vendor Apple
Public PoC No

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 11

Configuration From (including) Up to (excluding)
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
24.0.0 24.001.30264
Adobe Acrobat_Dc
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
15.008.20082 25.001.20693
Adobe Acrobat_Reader_Dc
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
15.008.20082 25.001.20693
Apple Macos
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
20.001.30002 20.005.30793
Adobe Acrobat_Reader
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
20.001.30002 20.005.30791
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
20.001.30002 20.005.30791
Adobe Acrobat_Reader
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
20.001.30002 20.005.30791
Apple Macos
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*