{"id":"CVE-2025-64786","title":"Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass","summary":"Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-347"],"vendor":"adobe","product":"acrobat","affected":["acrobat >= 20.001.3005, < 20.005.30838","acrobat_dc < 25.001.20997","acrobat_reader >= 20.001.3005, < 20.005.30838","acrobat_reader_dc < 25.001.20997","acrobat >= 24.001.20604, < 24.001.30307","acrobat >= 24.001.20604, < 24.001.30308"],"patched":["acrobat 24.001.30308","acrobat_dc 25.001.20997","acrobat_reader 20.005.30838","acrobat_reader_dc 25.001.20997"],"published":"2025-12-09","updated":"2026-09-25","sourceUpdated":"2026-09-25T23:10:00.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64786","references":[{"url":"https://helpx.adobe.com/security/products/acrobat/apsb25-119.html","label":"psirt@adobe.com"}],"tags":["nvd"],"epss":0.00435,"epssPercentile":0.35208,"ingestedAt":"2026-09-25T23:21:16.905Z","slug":"CVE-2025-64786","body":"## Overview\n\nAcrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue requires user interaction with a cryptographic signature.\n\n## Affected\n\n- `acrobat >= 20.001.3005, < 20.005.30838`\n- `acrobat_dc < 25.001.20997`\n- `acrobat_reader >= 20.001.3005, < 20.005.30838`\n- `acrobat_reader_dc < 25.001.20997`\n- `acrobat >= 24.001.20604, < 24.001.30307`\n- `acrobat >= 24.001.20604, < 24.001.30308`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `acrobat 24.001.30308`\n- `acrobat_dc 25.001.20997`\n- `acrobat_reader 20.005.30838`\n- `acrobat_reader_dc 25.001.20997`","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}