Impact
Acrobat Reader contains a use‑after‑free that can allow arbitrary code execution in the context of the current user. Exploitation requires a victim to open a malicious PDF. The flaw is a classic memory‑safety weakness and is labeled CWE‑416.
Affected Systems
Adobe Acrobat 2024, Acrobat Reader, and Adobe Acrobat desktop products are potentially affected. The CVE does not list specific vulnerable versions, so users should verify their product version against Adobe’s advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires user interaction – a user must open a malicious PDF – so risk is heightened in environments that frequently process unknown documents.
OpenCVE Enrichment