Impact
Acrobat Reader is vulnerable to a Use After Free bug that can be triggered by opening a specially crafted PDF file. The flaw allows an attacker to execute arbitrary code while the document is being processed, potentially compromising the confidentiality, integrity, or availability of the user’s system. The weakness is a classic memory management error, classified as CWE‑416.
Affected Systems
The affected products are Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The specific vulnerable revisions are not enumerated in the advisory, so all current releases before the security update should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 marks the vulnerability as high severity, and the nine‑year old EPSS data is not available. The flaw is not listed in the CISA KEV catalog. Exploitation requires the victim to manually open a malicious PDF, indicating it is a user‑interaction vulnerability rather than a remote trigger. Nonetheless, once invoked, the attacker can run code with the user’s privileges, posing a serious local impact.
OpenCVE Enrichment