CVE-2025-64786
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2025-64786 is an Improper Verification of Cryptographic Signature vulnerability (CWE-347) in Adobe Acrobat and Acrobat Reader that allows a security feature bypass, resulting in limited unauthorized write access. Affected versions include Acrobat Reader and Acrobat DC (Continuous track) prior to 25.001.20997, Classic 2024 track prior to 24.001.30307/30308, and Classic 2020 track prior to 20.005.30838, across both Windows and macOS. The vulnerability was published on December 9, 2025, with a patch released via Adobe security advisory APSB25-119 on December 9–12, 2025. It carries a CVSS v3.1 base score of 3.3 (Low) (Adobe Advisory).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), meaning the application fails to properly validate cryptographic signatures associated with PDF documents or related content. An attacker exploiting this flaw can bypass signature-based security controls to gain limited unauthorized write access. The attack vector is local, requires no privileges, but does require user interaction — specifically, a user must interact with a cryptographically signed document or feature. No public proof-of-concept code has been identified (Adobe Advisory).

Impact

Successful exploitation results in a security feature bypass that grants an attacker limited unauthorized write access to the affected system. There is no confidentiality or availability impact — the integrity impact is rated low and scoped to the local system. While the impact is constrained, bypassing cryptographic signature verification could undermine trust in signed PDF documents and allow subtle tampering in environments relying on document integrity controls (Adobe Advisory).

Mitigation and workarounds

Adobe has released patched versions addressing CVE-2025-64786 via security bulletin APSB25-119. Users should update to the following versions or later: Acrobat DC / Acrobat Reader DC (Continuous) — 25.001.20997; Acrobat / Acrobat Reader (Classic 2024) — 24.001.30307 or 24.001.30308; Acrobat / Acrobat Reader (Classic 2020) — 20.005.30838. No configuration-based workarounds have been published; upgrading to a patched version is the recommended remediation. Organizations should also implement strict access controls and monitor for unusual write activity as a defense-in-depth measure (Adobe Advisory).

Community reactions

Coverage of CVE-2025-64786 was largely bundled with broader reporting on Adobe's December 2025 Patch Tuesday release, which addressed numerous vulnerabilities across Acrobat and Reader. Security outlets including Sophos, CyberSecurityNews, and CyberPress covered the December 2025 Adobe patch batch, though most attention focused on higher-severity code execution flaws in the same advisory rather than this specific low-severity bypass (Sophos Blog, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management