CVE-2025-47111
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2025-47111 is a NULL Pointer Dereference vulnerability in Adobe Acrobat and Acrobat Reader that can cause application denial-of-service. Affected versions include Acrobat Reader/Acrobat DC (Continuous) prior to 25.001.20531, Acrobat/Acrobat Reader (Classic 2024) prior to 24.001.30254, and Acrobat/Acrobat Reader (Classic 2020) prior to 20.005.30774. Specifically, versions 24.001.30235, 20.005.30763, and 25.001.20521 and earlier are confirmed vulnerable. The vulnerability was published on June 10, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring when the application attempts to dereference a null pointer while processing a specially crafted file. Exploitation requires local access and user interaction — specifically, a victim must open a malicious PDF or other supported file type in the affected application. The attack vector is local (AV:L), with low attack complexity and no privileges required, but user interaction is mandatory. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).

Impact

Successful exploitation results in an application crash, causing a denial-of-service condition for the affected user. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged, meaning the vulnerability cannot be leveraged to affect other system components. While not enabling code execution or data exfiltration, exploitation could disrupt user productivity and prevent access to critical PDF documents (Adobe Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Adobe Advisory).

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability as part of security advisory APSB25-57. Users should update to the following versions or later: Acrobat DC / Acrobat Reader DC (Continuous) 25.001.20531, Acrobat 2024 / Acrobat Reader 2024 (Classic) 24.001.30254, and Acrobat 2020 / Acrobat Reader 2020 (Classic) 20.005.30774. As a general precaution, users should avoid opening PDF files from unknown or untrusted sources, and organizations should implement email and download filtering to reduce exposure to malicious files (Adobe Advisory).

Community reactions

Zscaler noted protection against this and other Adobe June 2025 vulnerabilities in their security advisories. Sophos covered the broader June 2025 patch landscape, which included this Adobe advisory. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-47111 has been identified, consistent with its medium severity and lack of known exploitation (Zscaler Advisory, Sophos News).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48373HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc
NoYesJul 17, 2026
CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 12, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management