3.3
CVE-2025-64787
- EPSS 0.02%
- Veröffentlicht 09.12.2025 20:21:03
- Zuletzt bearbeitet 28.04.2026 15:39:55
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
Acrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized write access. Exploitation of this issue requires user interaction with a cryptographic signature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Dc SwEditioncontinuous Version < 25.001.20997
Adobe ≫ Acrobat Reader SwEditionclassic Version >= 20.001.3005 < 20.005.30838
Adobe ≫ Acrobat Reader Dc SwEditioncontinuous Version < 25.001.20997
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.04 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| psirt@adobe.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.