CVE-2025-43578

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

27 Jun 2025, 15:14

Type Values Removed Values Added
First Time Adobe acrobat Reader
Adobe acrobat Reader Dc
Adobe
Adobe acrobat
Microsoft windows
Apple macos
Apple
Adobe acrobat Dc
Microsoft
CPE cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
References () https://helpx.adobe.com/security/products/acrobat/apsb25-57.html - () https://helpx.adobe.com/security/products/acrobat/apsb25-57.html - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2159 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2159 - Technical Description, Third Party Advisory

11 Jun 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : unknown
CWE CWE-125
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2159 -

10 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 19:15

Updated : 2025-06-27 15:14


NVD link : CVE-2025-43578

Mitre link : CVE-2025-43578


JSON object : View

Products Affected

adobe

  • acrobat_dc
  • acrobat
  • acrobat_reader
  • acrobat_reader_dc

apple

  • macos

microsoft

  • windows
CWE

No CWE.