Impact
An out‑of‑bounds read flaw in Adobe Acrobat Reader can expose sensitive memory contents. If an attacker crafts a malicious PDF, the flaw may reveal confidential data without authentication. The vulnerability is caused by a lack of bounds checking when processing the file, which corresponds to CWE‑125.
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader, and other Adobe Acrobat products are vulnerable. The issue applies to the editions listed by Adobe as part of the 2024 release series.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. Exploitation requires user action—specifically opening a malicious document—so the attack vector is user‑interaction based and cannot be executed remotely without such action. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting current exploitation risk is limited to targeted, social‑engineering scenarios.
OpenCVE Enrichment