CVE-2025-54255CWE-657

Acrobat Reader | Violation of Secure Design Principles (CWE-657)

Medium · published September 9, 2025

CVSS v3.1
4.0
EPSS
0%
Percentile
18.6
In the wild
Unconfirmed
What it is

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.

The record
Technical detail
CVSS v3.1
4.0 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00266 · 18.6th percentile
Weakness
CWE-657 · Violation of Secure Design Principles
Published
2025-09-09T20:10Z
EPSS history
Timeline
  • 09 SEP 20:10Z
    Acrobat Reader | Violation of Secure Design Principles (CWE-657)
    cvelistv5