CVE-2025-47111
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-06-10
Last updated on: 2025-07-25
Assigner: Adobe Systems Incorporated
Description
Description
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| adobe | acrobat_dc | to 25.001.20531 (exc) |
| adobe | acrobat_reader_dc | to 25.001.20531 (exc) |
| microsoft | windows | * |
| adobe | acrobat_dc | to 25.001.20529 (exc) |
| adobe | acrobat_reader_dc | to 25.001.20529 (exc) |
| apple | macos | * |
| adobe | acrobat | From 20.0 (inc) to 20.005.30774 (exc) |
| adobe | acrobat | From 24.0.0 (inc) to 24.001.30254 (exc) |
| adobe | acrobat_reader | From 20.0 (inc) to 20.005.30774 (exc) |
| apple | macos | * |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a NULL Pointer Dereference in Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier. It can be exploited when a user opens a malicious file, causing the application to crash and resulting in a denial-of-service condition.
How can this vulnerability impact me? :
The vulnerability can cause Acrobat Reader to crash, leading to a denial-of-service. This disrupts the normal use of the application and can interrupt workflows that depend on it.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70