Impact
Acrobat Reader is vulnerable to a use‑after‑free flaw that lets an attacker execute arbitrary code in the victim’s user context. The weakness, identified as CWE‑416, occurs when a malicious PDF file frees allocated memory and then attempts to access it again, allowing execution of crafted instructions. Successful exploitation can compromise any data the user has access to and bypass normal application controls.
Affected Systems
Adobe products affected include Acrobat 2024, Acrobat Reader, and Adobe Acrobat. Version details beyond the 2024 release are not specified in the advisory.
Risk and Exploitability
The CVSS score is 7.8, indicating a high‑severity vulnerability. EPSS data is not reported, and the issue is not listed in CISA KEV. The vulnerability requires user interaction—opening a malicious PDF—so the attack vector is user‑initiated local. While the lack of known public exploits reduces immediate risk, the high severity and lack of mitigation make it a priority to patch promptly.
OpenCVE Enrichment