Impact
Acrobat Reader contains an untrusted search path flaw that permits an attacker with high privileges to elevate their access level. The vulnerability requires the victim to open a malicious file, and it relies on conditions beyond the attacker’s direct control, meaning successful exploitation is not guaranteed without user interaction.
Affected Systems
Affected products include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat, with no documented version restrictions beyond the listed vendors.
Risk and Exploitability
The CVSS score of 4 indicates a moderate impact, and the EPSS score is not available, so exploitation likelihood is uncertain. The vulnerability is not listed in CISA’s KEV catalog. An attacker must already possess elevated privileges and convince a user to open a malicious document before the path selection flaw can be abused, reducing the overall threat but still enabling privilege escalation.
OpenCVE Enrichment