PT-2025-36950 · Adobe · Acrobat Reader

Published

2025-09-09

·

Updated

2025-11-11

·

CVE-2025-54257

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions 2020 and earlier Adobe Acrobat Reader versions 2020 and earlier Adobe Acrobat versions 24.001.30254 and earlier Adobe Acrobat Reader versions 24.001.30254 and earlier Adobe Acrobat versions 25.001.20672 and earlier Adobe Acrobat Reader versions 25.001.20672 and earlier
Description The software contains a use-after-free issue. Exploitation of this issue could allow an attacker to execute arbitrary code in the context of the current user. Exploitation requires user interaction, specifically opening a malicious file.
Recommendations Update Adobe Acrobat to a version later than 24.001.30254. Update Adobe Acrobat Reader to a version later than 24.001.30254. Update Adobe Acrobat to a version later than 25.001.20672. Update Adobe Acrobat Reader to a version later than 25.001.20672. Update Adobe Acrobat to a version later than 20.005.30774. Update Adobe Acrobat Reader to a version later than 20.005.30774.

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11063
CVE-2025-54257

Affected Products

Acrobat Reader