Out-of-Bounds Read in Adobe Acrobat Reader JPEG2000 Parsing Leaks Sensitive Memory
AI analysis
Adobe Acrobat Reader is affected by an out-of-bounds read vulnerability (CWE-125) in its parsing of JPEG2000 image data, per the ZDI advisory (ZDI-26-659), which could allow disclosure of sensitive memory contents. The flaw is triggered when a victim opens a maliciously crafted file, meaning user interaction is required for exploitation. A successful attack results in information disclosure (high confidentiality impact, no integrity or availability impact), and the local attack vector and user interaction requirement cap the CVSS 3.1 score at 5.5 (medium). All users running affected versions of Acrobat Reader are potentially exposed. As of now there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Update Acrobat Reader to the patched release identified in Adobe's security bulletin for this CVE (no fixed version number is provided in the source data); confirm the installed version via Help > About and update via Help > Check for Updates. Because exploitation requires opening a malicious file, users should avoid opening PDFs from untrusted sources until patched. No public PoC or in-the-wild exploitation is known, so this can be handled through routine patch cycles rather than emergency response.
Affected
| Adobe Acrobat Reader DC (Acrobat Reader) | — |
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader) — Estimate based on Acrobat Reader's near-ubiquitous deployment as the default PDF viewer on Windows and macOS endpoints, with Adobe historically reporting hundreds of millions of users; all users of affected versions are potentially exposed…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.