CVE-2025-54255
MEDIUMDescription
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
Is your site exposed to CVE-2025-54255?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat_dc |
| adobe | acrobat_reader_dc |
| apple | macos |
| microsoft | windows |
| adobe | acrobat |
| adobe | acrobat_reader |
| microsoft | windows |
| adobe | acrobat |
| adobe | acrobat_reader |
| apple | macos |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-54255? +
How severe is CVE-2025-54255? +
What products are affected by CVE-2025-54255? +
How do I check if I'm vulnerable to CVE-2025-54255? +
Related Vulnerabilities
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack …
Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect …
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service …
ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can …
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in …