Impact
Acrobat Reader is affected by a prototype‑pollution flaw that allows malicious code in a PDF to modify the prototype of JavaScript objects. This can lead to arbitrary file system reads, enabling an attacker to access sensitive files and directories outside the intended access scope. The impact is primarily confidentiality loss through unauthorized disclosure of files the user should not see, with scope expanded to any files the current user can read.
Affected Systems
The susceptible products include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The CVE does not list specific revision numbers, so installations of these products prior to any official remediation are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. EPSS data is not available, and it is not listed in the CISA KEV catalog. Exploitation requires user interaction; the victim must open a malicious PDF file to trigger the prototype pollution. Because scope is changed, the attacker can read files owned by the current user and any other files the user has permissions for, creating a significant risk of data exposure.
OpenCVE Enrichment