AI analysis
Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that an attacker can leverage for arbitrary code execution. The flaw is triggered when a victim opens a maliciously crafted file, such as a booby-trapped PDF, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the currently logged-in user, which could allow installation of malware, data theft, or further lateral movement on the workstation. Anyone running an affected release of Adobe Acrobat Reader is exposed; the source data does not enumerate specific affected version ranges, so defenders should consult Adobe's security bulletin (APSB) for exact versions and platforms. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.2%.
What to do: Check installed Acrobat Reader versions in your estate and apply Adobe's patched release as soon as it is available per the Adobe security bulletin (APSB) referenced in the advisory, since the source data does not list fixed build numbers. Until patched, caution users against opening PDFs from untrusted or unexpected sources, as exploitation requires a victim to open a malicious file. No public exploit exists yet and EPSS is low, so treat this as a routine patch-cycle priority rather than an emergency, but verify completion once updates ship.
Estimated exposure
masshundreds of millions of desktop installations worldwide — Acrobat Reader is the dominant PDF reader with a long-standing installed base commonly cited in the hundreds of millions of users, making this a mass-exposure product despite the lack of per-version counts in the data.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.