Impact
Acrobat Reader is affected by a heap‑based buffer overflow that can expose sensitive data stored in memory. The flaw does not grant arbitrary code execution but can leak confidential information if an attacker succeeds. The vulnerability is identified as CWE‑122, indicating that improper bounds checking on a heap buffer is the cause. Users can be affected when they open a maliciously crafted file.
Affected Systems
Adobe products including Acrobat 2024, Acrobat Reader, and Adobe Acrobat are affected. No specific version numbers are listed, so any installation of these products may be vulnerable until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 5.5 classifies the weakness as moderate, reflecting that exploitation requires user interaction – the victim must open the malicious file – and does not automatically grant high‑level privileges. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating that no large‑scale exploits are known. Nonetheless, because sensitive memory contents could be disclosed, the potential impact on confidentiality justifies monitoring and mitigation actions.
OpenCVE Enrichment