Impact
This vulnerability is a use‑after‑free flaw in Adobe Acrobat products that allows an attacker to execute arbitrary code with the privileges of the user who opens a malicious PDF. The flaw can be triggered when a user opens a crafted document, and the victim may run arbitrary machine code or elevate privileges. The underlying weakness is improper handling of freed memory (CWE-416).
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader, and other versions of Adobe Acrobat are affected. The CVE data lists the specific product families but does not provide individual version ranges; users should refer to Adobe’s security advisory for exact release information.
Risk and Exploitability
The vulnerability scores a 7.8 on the CVSS scale, indicating a high severity level. No EPSS score is reported, so the likelihood of real‑world exploitation cannot be precisely quantified, yet the requirement for user interaction makes the attack vector a “user‑initiated” one. The issue is not listed in the CISA KEV catalog, so there is no known active exploitation reported at this time. The flaw is a deterministic issue that can be triggered by any maliciously crafted PDF and only requires the victim to open it, making it potentially appealing to threat actors who rely on social engineering or delivery through captive portals.
OpenCVE Enrichment