CVE-2025-64899
Adobe Acrobat Reader Continuous vulnerability analysis and mitigation

Overview

CVE-2025-64899 is an out-of-bounds read vulnerability (CWE-125) in Adobe Acrobat and Acrobat Reader that can allow an attacker to execute arbitrary code in the context of the current user. It affects Acrobat Reader DC (Continuous) versions prior to 25.001.20997, Acrobat DC (Continuous) versions prior to 25.001.20997, Acrobat Classic 2024 versions prior to 24.001.30307/30308, and Acrobat Classic 2020 versions prior to 20.005.30838; specifically, versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, and 20.005.30803 and earlier are confirmed affected. The vulnerability was published on December 9, 2025, with a patch released on December 12, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, ZDI).

Technical details

The root cause is an out-of-bounds read (CWE-125) triggered during the parsing of a specially crafted file, causing the application to read past the end of an allocated memory structure. This memory corruption condition can be leveraged to achieve code execution in the context of the current user, potentially bypassing security protections. The attack vector is local (the malicious file must be delivered to and opened by the victim), requires no privileges, but does require user interaction — the victim must open a malicious document. The Zero Day Initiative published an advisory (ZDI-25-1043) covering this vulnerability (ZDI, Adobe Advisory).

Impact

Successful exploitation grants an attacker code execution with the privileges of the current user, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive data, modify files, install malware, or use the compromised session as a foothold for lateral movement within a network. The scope is limited to the local user context, but on systems where users operate with elevated privileges, the impact could be significantly broader (Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted PDF or supported file format that triggers an out-of-bounds read during parsing in Adobe Acrobat Reader.
  2. Deliver the file: The attacker distributes the malicious file via phishing email, malicious website, or other social engineering vector to a target running a vulnerable version of Acrobat Reader.
  3. Induce user interaction: The victim is tricked into opening the malicious file with a vulnerable version of Adobe Acrobat or Acrobat Reader.
  4. Trigger the vulnerability: Upon opening, the file parser reads past the end of an allocated memory buffer (out-of-bounds read), corrupting memory in a way that can be leveraged for code execution.
  5. Execute arbitrary code: The attacker's payload executes in the context of the current user, potentially enabling installation of malware, credential theft, or further lateral movement (Adobe Advisory, ZDI).

Indicators of compromise

  • Network: Unexpected outbound connections from the Acrobat Reader process (e.g., AcroRd32.exe or Acrobat.exe) to unknown external IPs or domains shortly after a file is opened.
  • Process: Unusual child processes spawned by AcroRd32.exe or Acrobat.exe (e.g., cmd.exe, powershell.exe, curl, wget, or scripting engines).
  • File System: Unexpected files written to user temp directories or startup folders by the Acrobat process; new executables or scripts created in %APPDATA% or %TEMP%.
  • Logs: Application crash logs or Windows Event Log entries indicating access violations or abnormal termination of Acrobat Reader processes; security logs showing process creation events with Acrobat as the parent process.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Acrobat DC and Acrobat Reader DC (Continuous) should be updated to version 25.001.20997 or later; Acrobat Classic 2024 should be updated to 24.001.30307 or 24.001.30308; and Acrobat Classic 2020 should be updated to 20.005.30838 or later. Users should apply updates immediately via Adobe's built-in update mechanism or by downloading directly from Adobe. As interim mitigations, organizations should implement email and web filtering to block potentially malicious PDF attachments, enforce application whitelisting, and educate users about the risks of opening unsolicited documents (Adobe Advisory).

Community reactions

Sophos noted this vulnerability as part of a significant December 2025 Patch Tuesday release, describing it as a "big finish to 2025" in terms of patch volume (Sophos). Security news outlets including CyberPress, CyberSecurityNews, and UnderCodeNews covered the vulnerability, highlighting the risk of arbitrary code execution via malicious PDF files (CyberPress, CyberSecurityNews). The Zero Day Initiative published a dedicated advisory (ZDI-25-1043), and FortiGuard added IPS coverage in updates 35.130 and 35.136. Community sentiment broadly emphasized the importance of prompt patching given the high CVSS score and the ubiquity of Adobe Acrobat in enterprise environments.

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Reader Continuous vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-47955HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 09, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management