CVE-2025-64786

LOW

Adobe Acrobat < 20.005.30838 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue requires user interaction with a cryptographic signature.

Scores

CVSS v3 3.3
EPSS 0.0003
EPSS Percentile 8.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (5)
adobe/acrobat 20.001.3005 - 20.005.30838
Adobe/Acrobat Reader < 20.005.30803
adobe/acrobat_dc < 25.001.20997
adobe/acrobat_reader 20.001.3005 - 20.005.30838
adobe/acrobat_reader_dc < 25.001.20997
Published Dec 09, 2025
Tracked Since Feb 18, 2026