Adobe Reader and Acrobat vulnerable to attack — what to do now
Adobe Reader and Acrobat security flaws affect Macs, PCs alike
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
If you use Adobe Acrobat Reader to read PDFs, or Adobe Acrobat to create them, then it's time to update. Adobe yesterday (Nov. 3) released new versions of both, for Mac and PC alike, to fix several severe security flaws.
There are 14 vulnerabilities in all, Adobe wrote in its security bulletin, ranging in severity from "Critical" to "Important." The three in the former category all permit arbitrary code execution — i.e. a rogue PDF can use the flaws to hack your PC or Mac.
- Best PDF reader apps for iOS and Android
- The best PDF editors to keep your documents sorted
- Best Black Friday deals you can get now
Other flaws permit information disclosure (access to private data such as passwords) and local privilege escalation (the PDF gets administrative powers on the machine).
The affected programs are the Mac and Windows versions of Acrobat DC, Acrobat 2020, Acrobat 2017, Acrobat Reader DC, Acrobat Reader 2020 and Acrobat Reader 2017. ("DC" stands for "Document Cloud"; it's the 2015 version but gets new features the others don't.)
How to update Adobe Acrobat or Acrobat Reader
To manually update any one of these programs, open the program, click Help in the upper left corner and scroll to and select Check for Updates. An updater window will pop open, check for updates and prompt you to download and install whatever is available. You'll have to close your Reader program while the updater works.
You can also just leave the program open and it should eventually notice that an update is ready for download and installation. Or you can start all over again with a new copy of Reader DC from https://get2.adobe.com/reader/. (Just be sure to uncheck the unwanted-program options before you start the download.)
The vulnerable version numbers are 2020.012.20048 and earlier for Acrobat and Reader DC; 2020.001.30005 and earlier for Acrobat and Reader 2020; and 2017.011.30175 and earlier for Acrobat and Reader 2017.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
We ran the update for Acrobat Reader DC for Windows and ended up with version 20.012.20064.
To be honest, you don't need the free Adobe Acrobat Reader to view PDFs. Any modern desktop web browser will do.
Nor do you need the paid Adobe Acrobat to create or edit PDFs. Because Adobe released the Portable Document Format to the public domain in 2008, the format is now an open standard. We've got a list of the best PDF editors as well as the best free PDF editors.

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.
