Impact
Acrobat Reader contains an out‑of‑bounds read flaw that can expose sensitive memory contents. When a malicious file is processed, the application may read data beyond the intended buffer, resulting in leakage of private data. The vulnerability specifically enables disclosure of contents in the victim’s memory space, compromising confidentiality.
Affected Systems
Adobe products affected include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. No specific version numbers are listed in the CNA data; the CVE affects all current releases of these products.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. Because exploitation requires the user to open a malicious file, the attack vector is user‑initiated and likely involves social engineering. The EPSS score is unknown, and the flaw is not yet listed in CISA’s KEV catalog. Consequently, the risk is moderate but non‑zero, and timely remediation is advised.
OpenCVE Enrichment