Impact
Acrobat Reader contains a use‑after‑free flaw that can expose sensitive data stored in memory. It is a memory‑corruption issue that does not provide code execution but can leak private information. An attacker could craft a malicious file that, when opened, causes the application to read freed memory and disclose its contents.
Affected Systems
Affected products include Adobe Acrobat 2024, Adobe Acrobat Reader, and the Adobe Acrobat family. Version details are not specified, but any installation of the listed products that predates the latest security update is susceptible.
Risk and Exploitability
The CVSS score of 5.5 reflects a moderate risk to confidentiality. EPSS data are unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited at present. Successful exploitation requires user interaction: a victim must open a crafted PDF file. Attackers would need to deliver or convince the victim to open such a file, limiting the attack surface but still presenting a tangible threat to organizations handling sensitive documents.
OpenCVE Enrichment