Avvisi di Sicurezza Zscaler

Consulenza sulla sicurezza - dicembre 09, 2025

Zscaler protects against 4 new vulnerabilities for Adobe Acrobat and Reader

Zscaler, working with Microsoft through their MAPP program, has proactively deployed protection for the following 4 vulnerabilities included in the December 2025 Adobe security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the December release and deploy additional protections, as necessary.

APSB25-119 – Security updates available for Adobe Acrobat and Reader.

Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address critical and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution and security feature bypass.

Affected Software

  • Acrobat DC Continuous 25.001.20982 and earlier versions for Windows & macOS
  • Acrobat Reader DC Continuous 25.001.20982 and earlier versions for Windows & macOS
  • Acrobat 2024 Classic 2024 24.001.30264 and earlier versions for Windows & 24.001.30273 and earlier for macOS
  • Acrobat 2020 Classic 20.005.30793 and earlier versions for Windows & 20.005.30803 and earlier for macOS
  • Acrobat Reader 2020 Classic 2020 20.005.30793 and earlier versions for Windows & 20.005.30803 and earlier for macOS

CVE-2025-64785 – Untrusted Search Path vulnerability leading to Arbitrary code execution. 

Severity: Critical

Subscription Required

  • Advanced Threat Protection 

CVE-2025-64786 – Improper Verification of Cryptographic Signature vulnerability leading to Security feature bypass. 

Severity: Moderate

Subscription Required

  • Advanced Threat Protection 

CVE-2025-64787 – Improper Verification of Cryptographic Signature vulnerability leading to Security feature bypass. 

Severity: Moderate

Subscription Required

  • Advanced Threat Protection 

CVE-2025-64899 – Out-of-bounds Read vulnerability leading to Arbitrary code execution. 

Severity: Critical

Subscription Required

  • Advanced Threat Protection