Impact
This vulnerability is an integer underflow (wrap or wraparound) that allows an attacker to access sensitive memory areas, potentially exposing confidential data. The flaw arises when an operation does not properly check the bounds of an input value, causing arithmetic calculations to wrap around and read unintended memory. The result can be a disclosure of arbitrary information stored in memory, which is a confidentiality risk and consistent with CWE-191.
Affected Systems
Affected systems include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The CVE data lists these vendors and products but does not specify particular patches or versions, so users should verify the presence of the fix in their installed software.
Risk and Exploitability
The CVSS score is 5.5, indicating a medium severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious PDF file. Therefore the attack vector is file-based and depends on the victim's careful handling of attachments. Given the moderate CVSS rating, the likelihood of exploitation appears limited, though the vulnerability remains exploitable if the target’s environment permits loading of compromised PDFs.
OpenCVE Enrichment