Impact
Acrobat Reader is vulnerable to a double free flaw (CWE‑415) that can allow an attacker to execute arbitrary code in the context of the user who opens a malicious file. The flaw occurs when the program frees the same memory twice during document parsing, yielding undefined behavior that an attacker can craft into a code execution scenario. Successful exploitation would give the attacker privileges of the user running the reader, enabling any action permitted to that user.
Affected Systems
Adobe products affected are Acrobat 2024, Acrobat Reader, and Adobe Acrobat for all platforms. Because no specific version ranges are provided, the vulnerability is believed to exist in any build of these products that was in use before the vendor's security release.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the requirement for user interaction limits the exploitation to scenarios where a victim opens a malicious PDF. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed active exploits. However, the potential for arbitrary code execution still necessitates prompt remediation once the fix is deployed.
OpenCVE Enrichment