Impact
Acrobat Reader suffers an out-of-bounds write that can lead to arbitrary code execution when a malicious PDF is opened by a user. The flaw allows an attacker to overrun memory bounds in order to inject and run code under the victim’s user context. This results in a full compromise of confidentiality, integrity, and availability within the user’s environment.
Affected Systems
Adobe’s Acrobat 2024, Acrobat Reader, and Adobe Acrobat are impacted. Specific version details were not provided, so any instance of these products that has not received the latest security update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 signifies high severity. Exploitation requires the victim to open a crafted file, indicating a user interaction vector. No EPSS information is available and the vulnerability is not listed in CISA’s KEV catalogue, suggesting it may not yet be widely exploited in the wild.
OpenCVE Enrichment