Impact
Acrobat Reader is vulnerable to uncontrolled resource consumption. The flaw, labeled as CWE-400, occurs when the application processes a specially crafted file, potentially exhausting CPU, memory or disk space. This resource exhaustion can cause the application to become unresponsive or terminate, resulting in a denial‑of‑service condition for the end user. The vulnerability does not grant the attacker additional privileges, modify data, or read confidential information.
Affected Systems
Adobe offers the affected products in its lineup under several product names. The flaw affects Adobe Acrobat Reader, Adobe Acrobat, and the 2024 edition of Acrobat. No specific patch version is listed, but users operating version 2024 or later should check Adobe’s security advisory for updates. The security notice does not isolate sub‑versions, so all releases within the mentioned product families are considered vulnerable.
Risk and Exploitability
With a CVSS score of 5.5, the vulnerability is rated as moderate. EPSS data is unavailable, and the flaw is not in CISA KEV, indicating no known active exploitation reports. Exploitation requires user interaction – the victim must open a malicious PDF. The attack path thus depends on social engineering or phishing vectors. Given the lack of remote access requirements and the controlled user interaction needed, the overall risk remains moderate.
OpenCVE Enrichment