Adobe Reader 25.1.21078

Adobe Reader 25.1.21078

Adobe Systems Inc.  ❘ 36.1MB  ❘ Freeware
Android iOS Windows Mac Linux
out of 3780 votes
Rank 1 among competitors

Get from Adobe Systems Inc.

Below you can a history of notable security vulnerabilities and breaches related to Adobe Reader.

Table of Contents

  1. CVE-2024-41896: Use-After-Free Vulnerability
  2. CVE-2024-49530: Arbitrary Code Execution
  3. CVE-2024-49535: XML External Entity (XXE) Vulnerability
  4. CVE-2024-49531: Null Pointer Dereference
  5. CVE-2024-39383: Proof-of-Concept Crash
  6. 2013 Adobe Data Breach
  7. Operation Aurora: 2010 Targeted Attacks
  8. JavaScript Vulnerabilities in PDFs
  9. Shadow Attacks on Signed PDFs

CVE-2024-41896: Use-After-Free Vulnerability

CVE-2024-41896 is a critical "use-after-free" vulnerability identified in Adobe Acrobat Reader. This flaw occurs when the program attempts to access memory that has already been freed, potentially allowing attackers to execute arbitrary code on the affected system. Adobe addressed this issue in a security update released in September 2024. More Information

CVE-2024-49530: Arbitrary Code Execution

CVE-2024-49530 is a critical vulnerability allowing arbitrary code execution due to a "use-after-free" condition. An attacker could execute malicious code with the privileges of the current user, potentially compromising the entire system. Adobe released a patch in December 2024. Adobe Security Bulletin

CVE-2024-49535: XML External Entity (XXE) Vulnerability

CVE-2024-49535 involves improper restriction of XML external entity references. Exploitation could lead to unauthorized access to sensitive information or denial of service. Adobe provided a security update in December 2024. Adobe Security Bulletin

CVE-2024-49531: Null Pointer Dereference

CVE-2024-49531 results from a null pointer dereference causing application crashes or denial of service, disrupting normal software operation. Adobe fixed this issue in December 2024. Adobe Security Bulletin

CVE-2024-39383: Proof-of-Concept Crash

CVE-2024-39383 can cause Adobe Acrobat and Reader to crash, but there were no reported active exploits as of August 2024. Adobe acknowledged the proof-of-concept existence. Adobe Security Bulletin

2013 Adobe Data Breach

In 2013, Adobe experienced a massive data breach impacting approximately 38 million users. Compromised data included encrypted passwords, credit card details, and product source code, raising significant concerns about infrastructure security. Details on Twingate

Operation Aurora: 2010 Targeted Attacks

Operation Aurora involved cyberattacks targeting companies including Adobe and Google through a zero-day vulnerability in Adobe Reader. Malicious PDF files installed malware, underscoring risks with unpatched software. More on Wired

JavaScript Vulnerabilities in PDFs

JavaScript within Adobe Reader PDFs enhances interactivity but has historically been exploited to execute malicious scripts, causing security breaches. Users frequently disable JavaScript to mitigate this risk. Adobe Acrobat on Wikipedia

Shadow Attacks on Signed PDFs

Shadow attacks exploit weaknesses in digital signatures allowing alteration of visible content without invalidating signatures, posing significant authenticity challenges for signed PDFs. PDF Vulnerabilities on Wikipedia


For up-to-date security information, always consult Adobe’s official Security Bulletins and Advisories.

Installations

31,510 users of UpdateStar had Adobe Reader installed last month.

Alternatives


PDFCreator

PDFCreator: Create and convert PDF files with ease!

Foxit PDF Reader

Efficient PDF viewing with Foxit Reader

FoxitReader

Efficient PDF Viewer with User-Friendly Interface

FlexiPDF

FlexiPDF: The Ultimate PDF Editing Tool

Nitro PDF Professional

Boost Your PDF Productivity with Nitro PDF Professional!

Adobe Acrobat Standard

Efficient PDF editing and collaboration with Adobe Acrobat Standard.
Secure and free downloads checked by UpdateStar

Stay up-to-date
with UpdateStar freeware.

Latest Reviews

Microsoft SQL Server 2008-Richtlinien Microsoft SQL Server 2008-Richtlinien
Powerful Data Management with SQL Server 2008
MiniTool Power Data Recovery MiniTool Power Data Recovery
Efficient Data Recovery Tool for All Users
Nero Burning ROM Nero Burning ROM
Nero Burning ROM: The Ultimate Disc Authoring Software for Windows
HopToDesk HopToDesk
HopToDesk: Seamless Remote Access and Support Solution
Java SE Development Kit Java SE Development Kit
Powerful Java Development Tools by Oracle
Final Dash 2.2 (New Dash Mode) Final Dash 2.2 (New Dash Mode)
Final Dash 2.2 (New Dash Mode) — fast, creative platformer with active community but bumpy updates
UpdateStar Premium Edition UpdateStar Premium Edition
Keeping Your Software Updated Has Never Been Easier with UpdateStar Premium Edition!
Google Chrome Google Chrome
Fast and Versatile Web Browser
Microsoft Edge Microsoft Edge
A New Standard in Web Browsing
Microsoft Visual C++ 2015 Redistributable Package Microsoft Visual C++ 2015 Redistributable Package
Boost your system performance with Microsoft Visual C++ 2015 Redistributable Package!
Microsoft OneDrive Microsoft OneDrive
Streamline Your File Management with Microsoft OneDrive
Microsoft Visual C++ 2010 Redistributable Microsoft Visual C++ 2010 Redistributable
Essential Component for Running Visual C++ Applications

Latest Updates


WeChat 4.1.11.24

Connect with friends and family with WeChat by 腾讯科技(深圳)有限公司

DAEMON Tools Ultra 7.1.0.1919

Mounting made easy with DAEMON Tools Ultra!

BitDefender Internet Security 27.0.60.341

Ultimate Online Protection with BitDefender Internet Security

GOM Player 2.3.121.5391

GOM Player: Your Ultimate Media Player

Avast Clear 26.7.11086

Avast Clear (formerly avast! Uninstall Utility) is a small utility to uninstall AVAST Software's antivirus software from your computer.

JRiver Media Center 36.0.21

Transform your digital media experience with JRiver Media Center.