CVE-2025-43550: Acrobat Reader | Use After Free (CWE-416)
Published Jun 10, 2025
·Updated
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
12 affected components
Adobe Acrobat Reader<25.001.20521
All of the following
Any of the following
Adobe Acrobat DC>=15.008.20082<25.001.20531
Adobe Acrobat Reader DC>=15.008.20082<25.001.20531
Microsoft Windows
All of the following
Any of the following
Adobe Acrobat DC>=15.008.20082<25.001.20529
Adobe Acrobat Reader DC>=15.008.20082<25.001.20529
Apple macOS
All of the following
Any of the following
Adobe Acrobat>=20.001.30002<20.005.30774
Adobe Acrobat>=24.0.0<24.001.30254
Adobe Acrobat Reader>=20.001.30002<20.005.30774
Any of the following
Apple macOS
Microsoft Windows
Event History
Jun 10, 2025
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43550?
CVE-2025-43550 is rated as a critical severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-43550?
To fix CVE-2025-43550, update Adobe Acrobat Reader to version 25.001.20522 or later.
3
Who is affected by CVE-2025-43550?
CVE-2025-43550 affects Adobe Acrobat Reader versions up to and including 25.001.20521.
4
What type of vulnerability is CVE-2025-43550?
CVE-2025-43550 is classified as a Use After Free vulnerability.
5
Can CVE-2025-43550 be exploited without user interaction?
Exploitation of CVE-2025-43550 requires user interaction, such as opening a malicious file.