Impact
Adobe Acrobat Reader contains an out‑of‑bounds read flaw that can expose sensitive data from memory if a user opens a crafted file. The weakness belongs to CWE‑125 and may reveal confidential information to an attacker. The impact is limited to the information disclosed and does not grant code execution or broader system compromise.
Affected Systems
The flaw affects Adobe Acrobat 2024, Adobe Acrobat Reader, and the generic Adobe Acrobat product line. Version details are not specified in the advisory, so all identified variants could be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction— the victim must open a malicious file. Thus the risk is primarily driven by user awareness and the presence of an up‑to‑date security update.
OpenCVE Enrichment