Impact
A heap‑based buffer overflow exists in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the same privileges as the user who opens a specially crafted file. The flaw occurs during the processing of certain PDF objects and requires the victim to interactively open the malicious document to trigger the overflow.
Affected Systems
Adobe Acrobat Reader, the widely used PDF viewer from Adobe, is the target of this vulnerability. No explicit version range is provided by the vendor, so any installation that has not yet applied the latest Adobe Acrobat Reader Security Update may be vulnerable. All systems that rely on Acrobat Reader for PDF viewing, including end‑user desktops and servers, could be affected.
Risk and Exploitability
The vulnerability scores high on the CVSS scale with a 7.8 rating. The EPSS score is reported to be less than 1%, indicating a very low likelihood of widespread exploitation, and the issue is not listed in the CISA KEV catalog. However, because exploitation requires the victim to open a malicious PDF, it is a user‑interaction attack. If an attacker succeeds, they can run code with the victim’s privileges, potentially leading to data exposure, further lateral movement, or compromise of the user’s system.
OpenCVE Enrichment