Impact
Acrobat Reader is affected by an integer overflow or wraparound vulnerability that could result in arbitrary code execution in the context of the current user. The flaw occurs when processing a maliciously crafted file, and the vulnerability may be triggered when a user opens that file.
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat are the affected products.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Exploitation requires user interaction, specifically opening a malicious file. Thus the attack surface is limited to users who inadvertently open such files, but the risk remains high until the vendor patch is applied.
OpenCVE Enrichment