
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64787 is an Improper Verification of Cryptographic Signature vulnerability (CWE-347) in Adobe Acrobat and Acrobat Reader that allows an attacker to bypass cryptographic protections and gain limited unauthorized write access. Affected versions include Acrobat Reader and Acrobat DC (Continuous track) prior to 25.001.20997, Acrobat Classic 2024 prior to 24.001.30307/30308, and Acrobat/Acrobat Reader Classic 2020 prior to 20.005.30838. The vulnerability was published on December 9, 2025, and a patch was made available via Adobe Security Bulletin APSB25-119 on December 12, 2025. It carries a CVSS v3.1 base score of 3.3 (Low) (Adobe Advisory, Feedly).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), meaning the application fails to properly validate cryptographic signatures on PDF documents or related data structures. This flaw maps to CAPEC-475 (Signature Spoofing by Improper Validation), where an attacker crafts or manipulates a document with an invalid or forged signature that the application incorrectly accepts as valid. Exploitation requires user interaction — specifically, a user must open or interact with a maliciously crafted PDF containing a manipulated cryptographic signature. The attack vector is local (AV:L), requiring the attacker to deliver a crafted file to the victim's system, with no privileges required on the attacker's part (Adobe Advisory, Feedly).
Successful exploitation results in a security feature bypass, specifically circumventing cryptographic signature verification in Adobe Acrobat/Reader, and grants the attacker limited unauthorized write access. The confidentiality impact is none, and availability is unaffected; the primary risk is to integrity — an attacker could compromise the trustworthiness of cryptographically signed PDF documents, potentially causing users or systems to accept tampered documents as authentic. The scope is unchanged and the impact is constrained to the local system context, limiting the potential for lateral movement or broad data exposure (Adobe Advisory, Feedly).
Adobe has released patches via Security Bulletin APSB25-119 (December 2025). Users should update to the following fixed versions: Acrobat DC and Acrobat Reader DC (Continuous) to 25.001.20997 or later; Acrobat Classic 2024 to 24.001.30307/30308 or later; Acrobat and Acrobat Reader Classic 2020 to 20.005.30838 or later. As interim measures, organizations should restrict local access to PDF applications, implement application whitelisting, and advise users to exercise caution when opening PDFs from untrusted sources. Adobe's automatic update mechanism can be used to apply patches promptly (Adobe Advisory).
The vulnerability was covered as part of Adobe's December 2025 Patch Tuesday cycle, with Sophos noting it as part of a significant end-of-year patch release (Sophos Blog). Security news outlets including CyberSecurityNews, CyberPress, and UnderCodeNews reported on the broader Adobe Acrobat/Reader vulnerability batch, though CVE-2025-64787 itself received limited individual attention given its low CVSS score. Community sentiment reflects routine patch urgency rather than alarm, consistent with the vulnerability's low severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."