Impact
A flaw in Adobe Acrobat and Acrobat Reader allows an attacker to read data beyond the bounds of a buffer. The vulnerability is an out‑of‑bounds read (CWE-125), which can expose portions of memory that may contain confidential information. The exposure is limited to the data accessible to the application at the time of the read and does not grant direct code execution or administrative privileges.
Affected Systems
The affected products are Adobe Acrobat 2024, Adobe Acrobat Reader and other Adobe Acrobat releases. Vulnerability impacts all operating systems where these products are installed unless mitigated by a subsequent update or patch.
Risk and Exploitability
The vulnerability carries a moderate CVSS score of 5.5. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet documented. Exploitation requires user interaction: the victim must open a crafted PDF file. No remote code execution is possible, but once the file is opened the application may leak parts of memory to the attacker. The risk to an asset depends on the sensitivity of the data in memory at the time of the read and the likelihood that an attacker can create or deliver a malicious file to the target.
OpenCVE Enrichment