---
id: CVE-2025-64899
title: >-
  Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982,
  24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read
  vulnerability when parsing a crafted file, which could result in a read past
  the end of an all…
summary: >-
  Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982,
  24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read
  vulnerability when parsing a crafted file, which could result in a read past
  the end of an all…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: adobe
product: acrobat
affected:
  - 'acrobat >= 20.001.3005, < 20.005.30838'
  - acrobat_dc < 25.001.20997
  - 'acrobat_reader >= 20.001.3005, < 20.005.30838'
  - acrobat_reader_dc < 25.001.20997
  - 'acrobat >= 24.001.20604, < 24.001.30307'
  - 'acrobat >= 24.001.20604, < 24.001.30308'
patched:
  - acrobat 24.001.30308
  - acrobat_dc 25.001.20997
  - acrobat_reader 20.005.30838
  - acrobat_reader_dc 25.001.20997
published: '2025-12-09'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64899'
references:
  - url: 'https://helpx.adobe.com/security/products/acrobat/apsb25-119.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00499
epssPercentile: 0.4021
ingestedAt: '2026-09-25T23:21:16.906Z'
---

## Overview

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `acrobat >= 20.001.3005, < 20.005.30838`
- `acrobat_dc < 25.001.20997`
- `acrobat_reader >= 20.001.3005, < 20.005.30838`
- `acrobat_reader_dc < 25.001.20997`
- `acrobat >= 24.001.20604, < 24.001.30307`
- `acrobat >= 24.001.20604, < 24.001.30308`

## Remediation

Upgrade past the affected range:

- `acrobat 24.001.30308`
- `acrobat_dc 25.001.20997`
- `acrobat_reader 20.005.30838`
- `acrobat_reader_dc 25.001.20997`
