Impact
Adobe Acrobat and Acrobat Reader contain a type confusion flaw that permits arbitrary code execution when a user opens a specially crafted file. The vulnerability can be leveraged by an attacker to run code with the privileges of the current user, potentially compromising the device and user data.
Affected Systems
Adobe releases affected by this flaw include Acrobat 2024, Acrobat Reader, and Adobe Acrobat. No specific version numbers are listed in the CNA data; all current releases are potentially vulnerable until a patch is applied.
Risk and Exploitability
The severity score of 7.8 indicates a high risk of exploitation. The EXSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to interact by opening a malicious file, making user awareness a critical defense factor. If exploited, the attacker can achieve full code execution under the victim’s user context.
OpenCVE Enrichment