Impact
A use after free bug in Adobe Acrobat allows an attacker to execute code in the context of the current user after the victim opens a malicious file. The flaw can lead to disclosure of sensitive data, modification of files, or full system compromise if the user’s privileges are high enough. The impact is confined to the account of the user who opens the vulnerable document.
Affected Systems
Adobe product family versions including Acrobat 2024, Acrobat Reader, and mainstream Adobe Acrobat installations are affected. No specific patch level or version numbers were listed, so any installation matching those product names is potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating medium to high severity. Exploitation requires user interaction and the delivery of a crafted PDF, so it cannot be triggered remotely without the victim opening a malicious file. No EPSS value is available and the issue has not yet been listed in the CISA KEV catalog, yet the attack can be executed locally and readily due to Acrobat’s widespread use. The potential for arbitrary code execution elevates the risk to high, particularly in environments where users handle untrusted documents.
OpenCVE Enrichment