Impact
Acrobat Reader contains a use‑after‑free flaw that allows an attacker to read data from freed memory, potentially leaking sensitive information. The vulnerability is a classic memory corruption issue categorized as CWE‑416. The exploit can result in accidental disclosure of confidential data stored in memory at the time the free occurs.
Affected Systems
The affected products are Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The advisory does not list a specific fixed version, so the risk applies to all variants that have not yet incorporated the Adobe update referenced in the help page.
Risk and Exploitability
The CVSS score of 5.5 places this issue in the medium range. Because exploitation requires that the victim open a malicious PDF file, the attack vector is user interaction, which reduces automated exploitation risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that it is not in current known exploit datasets.
OpenCVE Enrichment