CVE-2025-54255 Details
Description
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
A vulnerability has been identified in Adobe Acrobat and Reader applications for both Windows and macOS. This vulnerability, present in versions through 25.001.20672, 24.001.30254, 20.005.30774, and earlier, involves a violation of secure design principles that could allow for a security feature bypass. Notably, exploitation of this issue does not require user interaction.
Users are advised to update to the latest versions of Adobe Acrobat or Adobe Acrobat Reader. The latest versions can be downloaded from the Adobe website or via the Adobe Update mechanism. For IT administrators, updates can be deployed using preferred management tools or through direct installation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb25-85.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-657 | Violation of Secure Design Principles | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe acrobat | >= 24.0.0, < 24.001.30264 >= 20.001.30002, < 20.005.30793 >= 20.001.30002, < 20.005.30791 |
CPE
Remediation
| |
| adobe acrobat dc | >= 15.008.20082, < 25.001.20693 |
CPE
Remediation
| |
| adobe acrobat reader dc | >= 15.008.20082, < 25.001.20693 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| adobe acrobat reader | >= 20.001.30002, < 20.005.30791 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 2, 2025 | Modified Analysis | [email protected] |
| Oct 1, 2025 | CVE Modified | [email protected] |
| Sep 15, 2025 | Initial Analysis | [email protected] |
| Sep 9, 2025 | CVE Modified | [email protected] |
| Sep 9, 2025 | New CVE Received | [email protected] |