CVE-2025-54257
7.8Adobe · Acrobat Reader
A Use After Free vulnerability in Adobe Acrobat Reader allows attackers to achieve arbitrary code execution by tricking a user into opening a malicious file.
Executive summary
Adobe Acrobat Reader is affected by a critical Use After Free vulnerability that enables arbitrary code execution upon the opening of a malicious file.
Vulnerability
This is a Use After Free (CWE-416) memory corruption vulnerability. An unauthenticated attacker can achieve arbitrary code execution by persuading a victim to open a specially crafted malicious file, which triggers the memory error in the context of the current user.
Business impact
The ability to achieve arbitrary code execution poses a severe risk to organizational security, as it allows attackers to gain control over the victim's workstation. Given the CVSS score of 7.8, this vulnerability represents a high-severity threat that could lead to full system compromise, data exfiltration, or the deployment of secondary malware, potentially causing significant operational disruption.
Remediation
Immediate Action: Update Adobe Acrobat Reader to a version beyond 25.001.20672 as specified in the Adobe security bulletin APSB25-85.
Proactive Monitoring: Monitor endpoint security logs for unexpected child processes spawned by the Acrobat Reader application or unusual file write activity in user directories.
Compensating Controls: Implement email filtering and browser-based download protections to prevent users from accessing untrusted PDF documents from unknown sources.
Exploitation status
Public Exploit Available: No — exploit_available is unknown.
Analyst recommendation
This vulnerability presents a significant risk to end-user systems due to the potential for remote code execution. Security teams should prioritize the deployment of the vendor-provided patch across the enterprise immediately to eliminate the threat, as the requirement for user interaction is a low barrier for attackers using social engineering tactics.