Ad

CVE-2025-64899

HIGH CVSS 3.1: 7.8 EPSS 0.03%
Updated Dec 12, 2025
Adobe
Parameter Value
CVSS 7.8 (HIGH)
Affected Versions 20.001.3005 — 25.001.20997
Fixed In 20.005.30838
Type CWE-125 (Out-of-bounds Read)
Vendor Adobe
Public PoC No

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 8

Configuration From (including) Up to (excluding)
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
20.001.3005 20.005.30838
Adobe Acrobat_Dc
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
25.001.20997
Adobe Acrobat_Reader
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
20.001.3005 20.005.30838
Adobe Acrobat_Reader_Dc
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
25.001.20997
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
24.001.20604 24.001.30307
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Adobe Acrobat
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
24.001.20604 24.001.30308
Apple Macos
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*