Impact
Adobe Acrobat Reader is vulnerable to an incorrect authorization flaw that lets an attacker bypass a security feature and obtain write permission beyond what the file normally permits. This flaw is triggered by a malicious file that the user opens, and it changes the vulnerability scope, giving the attacker authority to modify files or settings traditionally protected from user control.
Affected Systems
The flaw affects Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat products. Specific version details are not disclosed in the advisory, so any installation of these products remains potentially at risk until updated.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity vulnerability. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a crafted file, so user interaction is a prerequisite. Because the attack changes severity scope and grants write access, an attacker could elevate privileges or compromise the integrity of the target system if they succeed.
OpenCVE Enrichment