Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
5

Potential vulnerability issue with Adobe Acrobat Reader

Community Beginner ,
Mar 17, 2025 Mar 17, 2025

Hi,

I've recently discovered that the latest version of Adobe Acrobat Reader v2025.1.20432.0 is still using vulnerable openssl library v3.0.14, however the new v3.0.16 is available. I am wondering if there is a planned fix for updating the openssl library from Adobe in order to mitigate vulnerabilities related to openssl library? Thanks in advance.

TOPICS
Security digital signatures and esignatures
8.9K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Mar 17, 2025 Mar 17, 2025

Hi @Soothing_Canvas8910

 

Thanks for reaching out with your question. I really appreciate this for reporting this. 

We will be checking internally with the team once we have any updates and will keep this thread updated.  

 

Thank you for your patience. 

 

~Tariq

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Mar 18, 2025 Mar 18, 2025

Hi @Tariq Ahmad , thanks for looking into this!

 

I wanted to add some extra info: I'm using Microsoft 365 for Business to manage the computers within my organisation. This includes Microsoft Defender for Business, which provides additional monitoring of the computers.

 

Since last week, MS Defender has been flagging Acrobat Reader v2025.1.20432.0 as containing a security vulnerability due to the vulnerable version of OpenSSL it's using.

 

The vulnerable file itself is:

c:\program files\adobe\acrobat dc\acrobat\rdrtools\libcrypto-3-x64.dll

 

...and as far as I'm aware, this file didn't exist with the previous version of Acrobat Reader - I believe it's new since version 2025.1.20432.0.

 

I've attached screenshots here showing the details of the Microsoft Defender report.

 

Therefore it's likely that other business and enterprise customers who are using Microsoft 365 will be seeing this report too, since last week, and will now be considering Acrobat Reader to be a security vulnerability.

 

I'm sharing this with you so you're aware that this is a potentially serious concern that Adobe needs to fix sooner than later! 🙂

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Mar 18, 2025 Mar 18, 2025

Thanks for sharing more details on this, @GermanKiwi

Really appreciate your time for sharing the details.

 

~Tariq 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Mar 20, 2025 Mar 20, 2025

In addition to c:\program files\adobe\acrobat dc\acrobat\rdrtools\libcrypto-3-x64.dll , also path c:\program files\adobe\acrobat dc\acrobat\tools\libcrypto-3-x64.dll contains the vulnerable file

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Mar 20, 2025 Mar 20, 2025

in Photoshop we have issue with below paths :

 

c:\program files\adobe\adobe photoshop 2024\libcrypto-3-x64.dll
c:\program files\adobe\adobe photoshop 2024\libssl-3-x64.dll
c:\program files\adobe\adobe photoshop 2025\libcrypto-3-x64.dll
c:\program files\adobe\adobe photoshop 2025\libssl-3-x64.dll
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Mar 24, 2025 Mar 24, 2025

Any news on this? It's been at least a week since Adobe was made aware of this, and almost two weeks since you released an Acrobat version, with a vulnerable version of openssl (libcrypto-3-x64.dll). Adobe Acrobat Reader is currently listed as the higest ranking security threat in Microsoft Defender, in our organization. due to this. It would be nice if Adobe acknowles that this is a problem, somewhere, but as far as I can tell, this is not listet anywhere, as a "known issues", and/or as a security bulletin, but only in this forum post.
I'm not really that concerned about the security risk, but more about the noise ths creates in our security systems.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Mar 24, 2025 Mar 24, 2025

Hi @JingsNo - Sorry for the troubled experience. 

This has been already reported internally to the product engineering team. Sadly there are no new updates that we can share publically on this issue. 

 

 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Apr 02, 2025 Apr 02, 2025

Has there been any update @Tariq Ahmad ? 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Apr 09, 2025 Apr 09, 2025

@Tariq Ahmad Any further news? Our management does not like seeing this vulnerability on our systems.  We are not comfortable accepting this risk. Eventually, they will select an alternative product and move on. 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Apr 02, 2025 Apr 02, 2025

Hi, 

 

Adobe Acrobat Reader, release of March 12, 2025, version 25.001.20432

is distributed with:

path

product

version

c:\program files\adobe\acrobat dc\acrobat\tools\libcrypto-3-x64.dll

openssl

3.0.14.0

c:\program files\adobe\acrobat dc\acrobat\rdrtools\libcrypto-3-x64.dll

openssl

3.0.14.0

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Apr 01, 2025 Apr 01, 2025

Any updates regarding this? All of our systems with Adobe Reader are all flagging the OpenSSL vulnerability for path "c:\program files\adobe\acrobat dc\acrobat\rdrtools\libcrypto-3-x64.dll"

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Apr 09, 2025 Apr 09, 2025

Adobe PSIRT team stated on 4/4: "Acrobat Desktop fixes the vulnerable 3rd party libraries at a regular cadence. Openssl will be upgraded to the latest version during their next release."

 

Any estimate on when the next release will take place? We are hoping to clean up our vulnerability reporting as it's currently flagging nearly every workstation in our org. 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Apr 16, 2025 Apr 16, 2025

A new update popped out today with version 25.001.20458 of Adobe Reader fixing the openssl library version to the newest one v3.0.16 in rdrtools path.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Apr 16, 2025 Apr 16, 2025

@Soothing_Canvas8910 awesome! Thanks for confirming this.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
May 26, 2025 May 26, 2025

C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\libcrypto-3.dll

C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\libssl-3.dll 

still on 3.0.15 @Tariq Ahmad when it´s planned to update this libraries too?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Mar 17, 2025 Mar 17, 2025

[MOVED TO THE ACROBAT READER DISCUSSIONS]


Acrobate du PDF, InDesigner et Photoshopographe
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Apr 01, 2025 Apr 01, 2025

I have the same with Photoshop and InDesign

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Apr 25, 2025 Apr 25, 2025

The newest version 25.001.20458 of Adobe Reader now contains vulnerable openssl libraries v3.0.15 in c:\program files\adobe\Acrobat dc\acrobat\plug_ins\libcrypto-3-x64.dll and c:\program files\adobe\Acrobat dc\acrobat\plug_ins\libssl-3-x64.dll. Microsoft Security Defender gave a security reccomendation of updating to v3.0.16 two days ago. Thought that will post it here since the problem is related to the previous issue. Thanks in advance.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Apr 25, 2025 Apr 25, 2025

Yeah I was about to post the same! @Tariq Ahmad Dar can you kindly ask your dev team to please update the OpenSSL libraries to version 3.0.16 and push out another update of Adobe DC for us? Thanks! 🙂

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Apr 25, 2025 Apr 25, 2025

Hi, @GermanKiwi - thanks for tagging me on this.
I will consult with the product team and share updates as soon as I have information. 


~Tariq

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
May 04, 2025 May 04, 2025

Dear @Tariq Ahmad could you please share an update, its been escalated by Auditor from State Government. 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
May 04, 2025 May 04, 2025

Just to add my voice to the chorus - I also need an update on when Adobe will updating the open ssl plugin.

 

It appears to impact most Adobe Products

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
May 11, 2025 May 11, 2025

@Tariq Ahmad Dar Can you please provide an update in this discussion

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
May 15, 2025 May 15, 2025

Hi @Kovac_NZ,

Sorry, no updates I am aware of. I am checking internally with the product engineering. 

Thank you for your patience and support.


~Tariq

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines