Adobe has released security updates to address critical vulnerabilities affecting Adobe Acrobat and Reader for Windows and macOS that could allow attackers to execute arbitrary code on vulnerable devices.
In total, the company today addressed 14 security flaws affecting the two products, 10 of which have been classified as critical or significant bugs.
These bugs could allow arbitrary code execution, local privilege escalation, information disclosure, arbitrary JavaScript execution , and dynamic library injection.

Adobe categorized the security updates as Priority 2 updates, meaning they address vulnerabilities without public exploits in products that have a "historically elevated risk."
The full list of vulnerabilities patched today is available in the table below, along with their severity ratings and assigned CVE numbers.

Adobe recommends that customers update vulnerable products to the latest versions as soon as possible to block attacks that could exploit unpatched installations.
Depending on their preferences, users can update their Adobe Acrobat and Reader products to the latest updated versions using one of the following approaches:
- Users can update their product installations manually by going to Help > Check for Updates.
- Products will be updated automatically, without requiring user intervention, when updates are detected.
- You can download the full Acrobat Reader installer from the Acrobat Reader Download Center.
IT admins can also deploy security updates to managed environments using corporate installers available through Adobe's public FTP server or using Windows / macOS remote management solutions .
Last month, Adobe patched 18 critical security flaws affecting ten of its Windows and macOS products that could be exploited to execute arbitrary code.
Software products patched by Adobe in October include Adobe Creative Cloud Desktop, Adobe InDesign, Adobe Media Encoder, Adobe Premiere Pro, Adobe Photoshop, Adobe After Effects, Adobe Animate, Adobe Dreamweaver, Adobe Illustrator and Marketo.
In October, the company also addressed a critical remote code execution vulnerability in Adobe Flash Player that could be exploited simply by visiting a malicious website.
