CVE-2025-64785
HIGHAdobe Acrobat < 20.005.30838 - Untrusted Search Path
Title source: ruleDescription
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue requires user interaction in that the user needs to open a malicious file.
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
17.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-426
Status
published
Products (5)
adobe/acrobat
20.001.3005 - 20.005.30838
Adobe/Acrobat Reader
< 20.005.30803
adobe/acrobat_dc
< 25.001.20997
adobe/acrobat_reader
20.001.3005 - 20.005.30838
adobe/acrobat_reader_dc
< 25.001.20997
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026