Impact
Adobe Acrobat Reader is vulnerable to a prototype pollution flaw that can allow a malicious PDF to modify JavaScript object prototypes. This flaw is described as CWE‑1321 and can be exploited to execute arbitrary code in the context of the current user when a PDF file is opened.
Affected Systems
Versions of Acrobat Reader 24.001.30356, 26.001.21367 and earlier are affected, including both classic and continuous build series. The flaw applies to installations running on the major operating systems supported by Acrobat Reader such as Windows and macOS.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of 10% indicates a low probability of widespread exploitation. The flaw is listed in the CISA KEV catalog, indicating that known exploits have been observed in the wild. Exploitation requires a user to open a specially crafted PDF file, making it a user‑interaction attack.
OpenCVE Enrichment