CVE-2025-54255

CWE-6574 documents4 sources
Severity
4.0MEDIUM
EPSS
0.1%
top 82.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.5 | Impact: 1.4

Affected Packages5 packages

NVDadobe/acrobat_reader20.001.3000220.005.30791
NVDadobe/acrobat_reader_dc15.008.2008225.001.20693
CVEListV5adobe/acrobat_reader25.001.20672
NVDadobe/acrobat24.0.024.001.30264+2
NVDadobe/acrobat_dc15.008.2008225.001.20693

🔴Vulnerability Details

2
CVEList
Acrobat Reader | Violation of Secure Design Principles (CWE-657)2025-09-09
GHSA
GHSA-qf3h-3jpx-7vjg: Acrobat Reader versions 242025-09-09