AI analysis
Adobe Acrobat Reader contains an integer underflow (wrap or wraparound) flaw, CWE-191, that occurs during PDF file parsing and can lead to the disclosure of sensitive memory. The vulnerability is triggered when a victim opens a maliciously crafted PDF file, making user interaction a required part of any attack. An attacker who successfully exploits it can read sensitive information from the application's memory, which could expose data in the affected process and potentially aid further attacks; the flaw does not by itself allow code execution. Anyone running the affected versions of Acrobat Reader (identified in related coverage as Acrobat Reader DC) who opens PDFs from untrusted sources is exposed. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.2% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Update Acrobat Reader to the latest release using Adobe's updater or by checking Adobe's security advisory for fixed versions, since the source data does not specify affected/fixed builds. Until patched, avoid opening PDFs from untrusted or unknown sources and caution users against doing so. Given no known exploitation and a low EPSS score, patching on your normal critical-update cycle is reasonable, but prioritize systems that routinely handle external PDFs.
Affected
| Adobe Acrobat Reader (Acrobat Reader DC) | — |
Estimated exposure
masshundreds of millions of potential users (Acrobat Reader is one of the most widely deployed desktop PDF viewers) — Acrobat Reader is the default PDF viewer on a vast share of desktops, with Adobe having publicly reported hundreds of millions of Acrobat/Reader users, though only installations that open untrusted PDFs are realistically exposed to this…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.