Impact
A heap-based buffer overflow has been discovered in Adobe Acrobat Reader and Adobe Acrobat. The flaw allows an attacker to execute arbitrary code within the victim’s user context when a malicious file is opened, potentially leading to data compromise, system takeover, or further lateral movement.
Affected Systems
Affected products are Adobe Acrobat 2024 and Adobe Acrobat Reader, all current releases of these packages are vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. Exploitation requires the user to interact by opening a crafted PDF, which is why the attack likelihood depends on user behavior and the presence of file restrictions. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no documented public exploitation yet, but the high impact and reasonable ease of delivery warrant urgent attention.
OpenCVE Enrichment