CVE-2025-64785
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2025-64785 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Acrobat and Acrobat Reader that allows attackers to execute arbitrary code in the context of the current user by redirecting the application's search path to a malicious program. It was disclosed on December 9, 2025, as part of Adobe's December 2025 Patch Tuesday security updates. Affected versions include Acrobat Reader DC and Acrobat DC prior to 25.001.20997, Acrobat Classic 2024 prior to 24.001.30308, and Acrobat Classic 2020 / Acrobat Reader Classic prior to 20.005.30838. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory).

Technical details

The root cause is classified as CWE-426 (Untrusted Search Path): when Adobe Acrobat or Reader searches for critical resources or programs, an attacker can manipulate the search path (e.g., via PATH environment variable hijacking or DLL/executable planting) to cause the application to load and execute a malicious program instead of the intended one. The attack vector is local, requires no special privileges, and exploitation requires the user to open a malicious file. This maps to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) (Adobe Advisory).

Impact

Successful exploitation results in arbitrary code execution in the context of the current user, yielding high confidentiality, integrity, and availability impact. An attacker who tricks a user into opening a crafted file could gain full control of the user's session, access sensitive documents, install malware, or pivot to other systems accessible by the compromised account. The scope is limited to the current user context, but on systems where users have elevated privileges, the impact could extend to broader system compromise (Adobe Advisory).

Exploitation steps

  1. Preparation: Identify a target system running a vulnerable version of Adobe Acrobat or Acrobat Reader (e.g., versions prior to 25.001.20997 for the Continuous track).
  2. Malicious program placement: Place a malicious executable or DLL in a directory that appears earlier in the system or user PATH environment variable than the legitimate program location, or in a directory where Acrobat searches for resources (e.g., the current working directory or a writable directory in the search path).
  3. Craft a malicious file: Create a specially crafted PDF or other file type handled by Acrobat that, when opened, triggers the application to search for and load the external resource or program.
  4. Deliver the file: Deliver the malicious file to the target user via phishing email, malicious download link, or other social engineering means.
  5. User opens the file: When the victim opens the malicious file in the vulnerable Acrobat/Reader version, the application resolves the search path and executes the attacker-controlled program instead of the legitimate one.
  6. Code execution achieved: The attacker's payload runs in the context of the current user, enabling actions such as establishing a reverse shell, exfiltrating data, or installing persistent malware (Adobe Advisory).

Indicators of compromise

  • File System: Unexpected executables or DLLs placed in directories included in the system or user PATH, particularly in writable locations such as %TEMP%, %APPDATA%, or the current working directory; files with names matching legitimate Adobe or system binaries.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl.exe, or unknown executables); processes running from unexpected directories.
  • Network: Outbound connections from Acrobat/Reader processes to unknown or suspicious IP addresses or domains, particularly shortly after a PDF file is opened.
  • Logs: Windows Event Logs (Security/System) showing process creation events (Event ID 4688) with Acrobat as the parent process and unexpected child processes; application logs showing resource loading from non-standard paths.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Acrobat Reader DC / Acrobat DC (Continuous): update to 25.001.20997 or later; Acrobat Classic 2024: update to 24.001.30308 or later; Acrobat Classic 2020 / Acrobat Reader Classic: update to 20.005.30838 or later. Organizations should deploy updates via endpoint management tools and enable automatic updates for Adobe products. As interim mitigations, restrict write access to directories in the system PATH, avoid opening PDF files from untrusted sources, and monitor for suspicious modifications to PATH environment variables (Adobe Advisory).

Community reactions

The vulnerability was covered as part of Adobe's December 2025 Patch Tuesday, which Sophos described as "a big finish to 2025" given the volume of patches released (Sophos). Security news outlets including CyberSecurityNews, CyberPress, and UnderCodeNews published coverage highlighting the arbitrary code execution risk to Windows and macOS users (CyberSecurityNews, CyberPress). Community reaction was moderate, with detection signatures added by Tenable (Nessus plugin 277939) and FortiGuard IPS, reflecting standard patch-Tuesday response without elevated alarm given the absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management