CVE-2025-43579

Severity
5.5MEDIUM
EPSS
0.4%
top 39.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateSep 16

Description

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDadobe/acrobat_reader20.001.3000220.005.30774
NVDadobe/acrobat_reader_dc15.008.2008225.001.20531+1
CVEListV5adobe/acrobat_reader25.001.20521
NVDadobe/acrobat20.001.3000220.005.30774+1
NVDadobe/acrobat_dc15.008.2008225.001.20531+1

🔴Vulnerability Details

2
GHSA
GHSA-gp97-h73h-crr6: Acrobat Reader versions 242025-06-10
CVEList
Acrobat Reader | Information Exposure (CWE-200)2025-06-10

💥Exploits & PoCs

1
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow2025-09-16