CVE-2025-64785

7.8

Adobe · Acrobat Reader

Adobe Acrobat Reader is affected by an untrusted search path vulnerability that may allow a local attacker to execute arbitrary code when a user opens a specifically crafted malicious file.

Executive summary

Adobe Acrobat Reader is vulnerable to an untrusted search path flaw that enables arbitrary code execution through user interaction, posing a high risk to endpoint security.

Vulnerability

This vulnerability involves an untrusted search path (CWE-426) where the application improperly locates critical resources. An attacker can manipulate this search path to force the application to execute a malicious program in the context of the current user, requiring successful user interaction to trigger the exploit.

Business impact

The potential for arbitrary code execution creates a significant risk of full system compromise for the affected endpoint. Given the CVSS score of 7.8, this vulnerability carries a high severity rating, as it allows attackers to gain the same privileges as the user running the application, potentially leading to unauthorized data access, lateral movement within the network, or the installation of persistent malware.

Remediation

Immediate Action: Update Adobe Acrobat Reader to the latest patched version as specified in the Adobe security advisory APSB25-119.

Proactive Monitoring: Monitor endpoint execution logs for suspicious process spawning behavior originating from the Acrobat Reader application.

Compensating Controls: Implement organizational policies that restrict the ability of standard users to modify system environmental variables or search paths, and utilize application control software to prevent the execution of untrusted binaries.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear and significant risk due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of Adobe Acrobat Reader to the latest version provided by the vendor. Users should be cautioned against opening suspicious PDF files from untrusted or unknown sources until the software has been updated to a secure version.

More Adobe CVEs

Sources