
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64899 is an out-of-bounds read vulnerability (CWE-125) in Adobe Acrobat and Acrobat Reader that can allow an attacker to execute arbitrary code in the context of the current user. It affects Acrobat Reader DC (Continuous) versions prior to 25.001.20997, Acrobat DC (Continuous) versions prior to 25.001.20997, Acrobat Classic 2024 versions prior to 24.001.30307/30308, and Acrobat Classic 2020 versions prior to 20.005.30838; specifically, versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, and 20.005.30803 and earlier are confirmed affected. The vulnerability was published on December 9, 2025, with a patch released on December 12, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI).
The root cause is an out-of-bounds read (CWE-125) triggered during the parsing of a specially crafted file, causing the application to read past the end of an allocated memory structure. This memory corruption condition can be leveraged to achieve code execution in the context of the current user, potentially bypassing security protections. The attack vector is local (the malicious file must be delivered to and opened by the victim), requires no privileges, but does require user interaction — the victim must open a malicious document. The Zero Day Initiative published an advisory (ZDI-25-1043) covering this vulnerability (ZDI, Adobe Advisory).
Successful exploitation grants an attacker code execution with the privileges of the current user, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive data, modify files, install malware, or use the compromised session as a foothold for lateral movement within a network. The scope is limited to the local user context, but on systems where users operate with elevated privileges, the impact could be significantly broader (Adobe Advisory).
AcroRd32.exe or Acrobat.exe) to unknown external IPs or domains shortly after a file is opened.AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget, or scripting engines).%APPDATA% or %TEMP%.Adobe has released patched versions addressing this vulnerability: Acrobat DC and Acrobat Reader DC (Continuous) should be updated to version 25.001.20997 or later; Acrobat Classic 2024 should be updated to 24.001.30307 or 24.001.30308; and Acrobat Classic 2020 should be updated to 20.005.30838 or later. Users should apply updates immediately via Adobe's built-in update mechanism or by downloading directly from Adobe. As interim mitigations, organizations should implement email and web filtering to block potentially malicious PDF attachments, enforce application whitelisting, and educate users about the risks of opening unsolicited documents (Adobe Advisory).
Sophos noted this vulnerability as part of a significant December 2025 Patch Tuesday release, describing it as a "big finish to 2025" in terms of patch volume (Sophos). Security news outlets including CyberPress, CyberSecurityNews, and UnderCodeNews covered the vulnerability, highlighting the risk of arbitrary code execution via malicious PDF files (CyberPress, CyberSecurityNews). The Zero Day Initiative published a dedicated advisory (ZDI-25-1043), and FortiGuard added IPS coverage in updates 35.130 and 35.136. Community sentiment broadly emphasized the importance of prompt patching given the high CVSS score and the ubiquity of Adobe Acrobat in enterprise environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."