
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47111 is a NULL Pointer Dereference vulnerability in Adobe Acrobat and Acrobat Reader that can cause application denial-of-service. Affected versions include Acrobat Reader/Acrobat DC (Continuous) prior to 25.001.20531, Acrobat/Acrobat Reader (Classic 2024) prior to 24.001.30254, and Acrobat/Acrobat Reader (Classic 2020) prior to 20.005.30774. Specifically, versions 24.001.30235, 20.005.30763, and 25.001.20521 and earlier are confirmed vulnerable. The vulnerability was published on June 10, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring when the application attempts to dereference a null pointer while processing a specially crafted file. Exploitation requires local access and user interaction — specifically, a victim must open a malicious PDF or other supported file type in the affected application. The attack vector is local (AV:L), with low attack complexity and no privileges required, but user interaction is mandatory. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).
Successful exploitation results in an application crash, causing a denial-of-service condition for the affected user. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged, meaning the vulnerability cannot be leveraged to affect other system components. While not enabling code execution or data exfiltration, exploitation could disrupt user productivity and prevent access to critical PDF documents (Adobe Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Adobe Advisory).
Adobe has released patched versions addressing this vulnerability as part of security advisory APSB25-57. Users should update to the following versions or later: Acrobat DC / Acrobat Reader DC (Continuous) 25.001.20531, Acrobat 2024 / Acrobat Reader 2024 (Classic) 24.001.30254, and Acrobat 2020 / Acrobat Reader 2020 (Classic) 20.005.30774. As a general precaution, users should avoid opening PDF files from unknown or untrusted sources, and organizations should implement email and download filtering to reduce exposure to malicious files (Adobe Advisory).
Zscaler noted protection against this and other Adobe June 2025 vulnerabilities in their security advisories. Sophos covered the broader June 2025 patch landscape, which included this Adobe advisory. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-47111 has been identified, consistent with its medium severity and lack of known exploitation (Zscaler Advisory, Sophos News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."