Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe acrobat Adobe acrobat Dc Adobe acrobat Reader Adobe acrobat Reader Dc Apple Apple macos Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Adobe
Adobe acrobat Adobe acrobat Dc Adobe acrobat Reader Adobe acrobat Reader Dc Apple Apple macos Microsoft Microsoft windows |
Wed, 12 Mar 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 11 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
Title | Acrobat Reader | Out-of-bounds Read (CWE-125) | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-03-11T18:10:14.018Z
Updated: 2025-03-12T13:08:25.246Z
Reserved: 2025-02-19T22:28:19.017Z
Link: CVE-2025-27164

Updated: 2025-03-12T13:08:25.246Z

Status : Analyzed
Published: 2025-03-11T18:15:34.437
Modified: 2025-04-28T16:48:33.017
Link: CVE-2025-27164

No data.