Adobe patches critical PDF zero-day flaw after months of hacker abuse
https://httnews.com/images/article-e8d2313a8ed0-1776229219.jpgAttack Underway Since February
Adobe on Wednesday issued an emergency update for a zero-day vulnerability in Acrobat DC, Acrobat Reader DC and 2017 versions that threat actors have exploited since at least February. The bug, tracked as CVE-2025-3041, is a use-after-free weakness rated critical that can allow remote code execution with the privileges of the current user simply by convincing a target to open a malicious PDF.
No User Interaction Required
Adobe credited researchers at cybersecurity company Trend Micro’s Zero Day Initiative for alerting the company to the in-the-wild attacks. In its advisory Adobe said the flaw “has been exploited in limited attacks” but offered no details on victimology or attribution. Because opening a booby-trapped file is usually enough to trigger the exploit, security teams regard the bug as a high-risk entry vector for ransomware and espionage campaigns.
Immediate Patching Urged
Fixed versions are Acrobat Reader 2025.001.20435 for the Continuous track, 2022.003.20655 for the Classic 2022 track and 2017.011.30191 for the 2017 track. Adobe, citing the active exploitation, pushed the patches outside its regular monthly schedule and urged Windows and macOS customers to “update as soon as possible.” IT administrators can force enterprise-wide installs via the RUM updater or by disabling JavaScript in PDF readers until reboot cycles are complete.
Historic Trend
CVE-2025-3041 is the second zero-day Adobe has patched in Acrobat products this year after CVE-2025-0103 closed in January, underscoring the software’s continued attractiveness to attackers who prize ubiquitous document workflows, researchers said.