Impact
Acrobat Reader is vulnerable to an out‑of‑bounds write that can lead to arbitrary code execution when a malicious file is opened. The flaw is triggered by user interaction, meaning an attacker must coax a victim to open the crafted PDF. The resulting code runs with the victim’s privileges, potentially compromising confidentiality, integrity, and availability of the affected system. The weakness is identified as CWE-787, a classic buffer overflow scenario that corrupts memory.
Affected Systems
Affected systems include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. No specific version numbers are provided, so any installation of these products is considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, so the attack vector is user‑interactive and relies on social engineering. This makes remote exploitation without user action unlikely, yet environments that readily accept PDF files remain exposed.
OpenCVE Enrichment