Out-of-Bounds Read Vulnerability in Adobe Acrobat Reader
CVE-2025-27163

5.5MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
11 March 2025

Summary

Adobe Acrobat Reader versions 24.001.30225, 20.005.30748, and 25.001.20428 and earlier are impacted by an out-of-bounds read vulnerability. This flaw allows an attacker to potentially access sensitive information from memory and may circumvent security measures like ASLR (Address Space Layout Randomization). Successful exploitation requires user interaction, as the victim must open a specially crafted malicious file for the vulnerability to be triggered.

Affected Version(s)

Acrobat Reader 0 <= 25.001.20428

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.