
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64785 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Acrobat and Acrobat Reader that allows attackers to execute arbitrary code in the context of the current user by redirecting the application's search path to a malicious program. It was disclosed on December 9, 2025, as part of Adobe's December 2025 Patch Tuesday security updates. Affected versions include Acrobat Reader DC and Acrobat DC prior to 25.001.20997, Acrobat Classic 2024 prior to 24.001.30308, and Acrobat Classic 2020 / Acrobat Reader Classic prior to 20.005.30838. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).
The root cause is classified as CWE-426 (Untrusted Search Path): when Adobe Acrobat or Reader searches for critical resources or programs, an attacker can manipulate the search path (e.g., via PATH environment variable hijacking or DLL/executable planting) to cause the application to load and execute a malicious program instead of the intended one. The attack vector is local, requires no special privileges, and exploitation requires the user to open a malicious file. This maps to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) (Adobe Advisory).
Successful exploitation results in arbitrary code execution in the context of the current user, yielding high confidentiality, integrity, and availability impact. An attacker who tricks a user into opening a crafted file could gain full control of the user's session, access sensitive documents, install malware, or pivot to other systems accessible by the compromised account. The scope is limited to the current user context, but on systems where users have elevated privileges, the impact could extend to broader system compromise (Adobe Advisory).
%TEMP%, %APPDATA%, or the current working directory; files with names matching legitimate Adobe or system binaries.AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl.exe, or unknown executables); processes running from unexpected directories.Adobe has released patched versions addressing this vulnerability: Acrobat Reader DC / Acrobat DC (Continuous): update to 25.001.20997 or later; Acrobat Classic 2024: update to 24.001.30308 or later; Acrobat Classic 2020 / Acrobat Reader Classic: update to 20.005.30838 or later. Organizations should deploy updates via endpoint management tools and enable automatic updates for Adobe products. As interim mitigations, restrict write access to directories in the system PATH, avoid opening PDF files from untrusted sources, and monitor for suspicious modifications to PATH environment variables (Adobe Advisory).
The vulnerability was covered as part of Adobe's December 2025 Patch Tuesday, which Sophos described as "a big finish to 2025" given the volume of patches released (Sophos). Security news outlets including CyberSecurityNews, CyberPress, and UnderCodeNews published coverage highlighting the arbitrary code execution risk to Windows and macOS users (CyberSecurityNews, CyberPress). Community reaction was moderate, with detection signatures added by Tenable (Nessus plugin 277939) and FortiGuard IPS, reflecting standard patch-Tuesday response without elevated alarm given the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."