Impact
Adobe Acrobat Reader contains an incorrect authorization flaw that permits a non‑privileged user to perform actions that require higher privileges. This vulnerability results in a change of scope and can grant the attacker elevated access to the system. It is classified as a CWE‑863 authorization flaw.
Affected Systems
Affected products include Adobe Acrobat 2024, Adobe Acrobat Reader, and other releases of Adobe Acrobat. The specific patch versions that fix the issue are not listed, so any version that lacks the official security update may be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must have a low‑privileged foothold to exploit the flaw, and no user interaction is required to trigger the incorrect authorization. This combination of high impact and ease of exploitation results in a significant risk to affected systems.
OpenCVE Enrichment