Impact
Acrobat Reader contains an out-of-bounds read vulnerability that can reveal sensitive memory contents. The flaw occurs when processing a malicious file crafted by an attacker, and its exploitation requires the user to open the file. Successful exploitation would expose confidential data to the attacker, compromising confidentiality.
Affected Systems
Adobe Acrobat 2024, Adobe Acrobat Reader and generic Adobe Acrobat products are affected. No specific version numbers are listed in the CNA data, so all builds within the mentioned product line must be considered at risk.
Risk and Exploitability
This issue has a CVSS score of 5.5, indicating a moderate severity. The exploit probability (EPSS) is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector involves user interaction: the victim must open a malicious file. Because the adversary needs only a social‑engineering step to get the file opened, the likelihood of exploitation depends on user behavior, but the potential impact is the disclosure of sensitive information if the exploit succeeds.
OpenCVE Enrichment