HomeUpdatesAdobe Acrobat Reader: Fixes for important vulnerabilities

Adobe Acrobat Reader: Critical Vulnerabilities Patched

Adobe has released new security updates for Adobe Acrobat Reader , addressing a number of vulnerabilities that could be exploited by attackers to execute arbitrary code or bypass basic protection mechanisms . The updates were announced in bulletin APSB25-119 on December 9 , 2025, and apply to Windows and macOS systems .

Adobe Acrobat Reader

Origin of vulnerabilities: Weaknesses in the PDF processing engine

According to Adobe, the specific issues are located at the very heart of Acrobat Reader: the engine PDF processing. The complexity of the platform and the handling of many data types make PDF products a frequent target for attacks. At the same time, simple errors in the way documents are loaded, rendered, or parsed can open the door to dangerous exploits.

See also: Zero-day Gogs vulnerability used in attacks

How vulnerabilities can be exploited by attackers

Two of the most serious flaws, which were fixed, allow arbitrary code execution via:

  • untrusted search path
  •  out-of-bounds read errors

Both bugs are rated CVSS 7.8, which is considered high risk, since an attacker can exploit them simply by convincing the victim to open a specially modified PDF.

Two more moderate-severity stem from improper verification of cryptographic signatures. With a CVSS score of 3.3, these vulnerabilities could allow an attacker to bypass security mechanismsby presenting a malicious document as trustworthy.

Adobe Acrobat Reader: Critical Vulnerabilities Patched

Which products are affected — Nearly the entire Acrobat ecosystem

The vulnerabilities touch a significant part of the Acrobat ecosystem:

  • Acrobat DC
  • Acrobat Reader DC
  • Acrobat 2024
  • Adobe Acrobat 2020
  • Adobe Acrobat Reader 2020

All current versions of these products are considered vulnerable. For this reason, Adobe recommends installing the new patches immediately.

See also: React2Shell exploit distributes crypto miners

New versions that fix problems

The versions that close the security gaps are:

  • Acrobat DC / Reader DC 25.001.20997
  • Acrobat 2024 24.001.30307 (Windows)
  • Acrobat 2024 24.001.30308 (macOS)
  • Acrobat 2020 20.005.30838 (on Windows and macOS)

Users can update either via Help > Check for Updates, or by enabling automatic updates, which are recommended for those who want continuous protection without manual intervention.

Critical role of IT administrators — Recommended upgrade practices

In business and enterprise environments, updates are typically installed centrally. Adobe recommends that IT administrators use their established methods, such as:

  • AIP-GPO for mass installations
  • Bootstrapper for gradual patch release
  • SCCM for installations in a Windows environment

Timely implementation of updates is especially critical in departments that handle confidential documents, such as legal departments, banks, or government agencies.

See also: .NET SOAPwn vulnerability allows RCE attack

No Active Exploits Yet — But the Risk Remains High

Although Adobe assures that there are no recorded attacks exploiting these vulnerabilities, this does not diminish the seriousness of the issue. History has shown that cybercriminals often target known vulnerabilities just days after they are publicly disclosed.

Therefore, the risk window remains open until the patches are fully implemented.

Adobe Acrobat Reader: Critical Vulnerabilities Patched

Why immediate information is so important

Acrobat is one of the most widely used tools for businesses and individuals. A PDF is not just a document, but hosts scripts, embedded files, forms and metadata that can be a vector of attack.

Failure to provide immediate information may expose:

  • corporate networks
  • employee endpoints
  • files with sensitive personal data

to significant risks.

Recommendation to organizations and users

Adobe is urging organizations to prioritize installing the new updates on all devices where Acrobat or Reader is used. For consumers, the process is quick and automated, while for businesses, it is another necessary step in maintaining a secure digital infrastructure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS