Impact
Acrobat Reader contains a use‑after‑free flaw that can be exploited to execute arbitrary code in the context of the user who opens a specially crafted PDF. The vulnerability arises when memory is deallocated, leaving a dangling pointer that a malicious file later dereferences, allowing code injection. Because the exploit requires the victim to open the file, the impact is limited to the rights of that user but can provide full control over the machine if successful.
Affected Systems
All installations of Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat are affected. No exact version range is supplied, so any release containing the vulnerable code must be examined and patched.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, which may reduce awareness. The requirement for user interaction – opening a malicious PDF – means attackers would likely rely on phishing or drive‑by tactics. Once triggered, the use‑after‑free can lead to arbitrary code execution, making the risk significant for affected users.
OpenCVE Enrichment