AI analysis
Adobe Acrobat Reader contains a use-after-free memory corruption vulnerability (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a maliciously crafted PDF file, meaning successful exploitation requires user interaction. An attacker who exploits it gains code execution with the privileges of the logged-in user who opened the file, potentially allowing malware installation or data theft on that endpoint. Anyone running an affected version of Acrobat Reader is exposed, and because Reader is opened on untrusted PDFs from email and the web, attack surface is broad despite the local attack vector. As of now there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Check Adobe's security bulletin for this CVE and update Acrobat Reader to the patched version it specifies for your platform. In the interim, warn users not to open PDFs from untrusted sources and consider blocking or sandboxing PDF attachments at the email gateway. Verify endpoint inventories for out-of-date Reader installations and confirm post-update that the fix is deployed.
Estimated exposure
masshundreds of millions of users (global installed base of Acrobat Reader) — Adobe Acrobat Reader is the dominant free PDF viewer with hundreds of millions of active users worldwide according to Adobe's own published figures, so essentially every organization and consumer endpoint fleet is plausibly affected until…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.