Impact
Acrobat Reader is vulnerable to a use‑after‑free flaw that can lead to arbitrary code execution in the context of the logged‑in user. The defect is a classic memory corruption error, categorized as CWE‑416, and occurs when a malicious document exposes the freed memory to further use. The impact is that an attacker who is able to craft a special PDF could potentially run arbitrary code with the victim’s privileges, enabling data disclosure, credential theft, or system compromise.
Affected Systems
Adobe products, including Acrobat 2024, Acrobat Reader, and Adobe Acrobat, are affected. The specific version ranges are not provided in the CVE data, so administrators should verify that all installations of these products are run with the latest updates and patches when released by Adobe.
Risk and Exploitability
The vulnerability scores a CVSS of 7.8, indicating a high severity level. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, implying a user‑interaction attack vector. Because of the high CVSS score and the nature of the flaw, the risk of exploitation is significant, especially in environments where users regularly open untrusted documents.
OpenCVE Enrichment