Impact
Acrobat Reader contains a Use After Free flaw that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability is triggered when a malicious PDF file is opened, leading the program to reference freed memory and grant the attacker the ability to inject and run code.
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader and Adobe Acrobat are affected. Users running any of these versions must verify their installed version and apply the available fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and while EPSS is not published, the requirement for user interaction limits the attack surface to social engineering or malicious files. The flaw is not listed in CISA KEV and no public exploits are reported, but the impact of arbitrary code execution warrants prompt remediation.
OpenCVE Enrichment