Impact
The vulnerability is an out-of-bounds write that can allow an attacker to execute arbitrary code in the context of the user who opens a malicious file. This flaw is identified as CWE-787, indicating a failure to properly check bounds before performing a memory write. If exploited, the attacker could gain full control over the victim’s system, tampering with data or installing malicious software.
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat products are affected. The advisory does not list specific patch versions; organizations should verify that their installations are at least at the latest release for each of these products.
Risk and Exploitability
The CVSS score of 7.8 places this flaw in the high‑severity range, while the EPSS score is not available, suggesting no publicly available exploitation data as of the latest update. The vulnerability requires user interaction—the victim must open a crafted PDF file. This limits attack surface to scenarios where malicious documents are delivered via email, web, or other media. Without such interaction, the flaw cannot be triggered, reducing the likelihood of opportunistic exploitation.
OpenCVE Enrichment