AI analysis
Adobe Acrobat Reader contains a use-after-free memory-corruption flaw (CWE-416) that can be triggered when the application processes a maliciously crafted file. Exploitation requires user interaction: the victim must open the malicious file, making this a local attack vector in which the user's own privileges are at stake. A successful attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity and availability of that user's environment. Any user running Adobe Acrobat Reader is potentially affected; the available data does not specify which version ranges are impacted, so consult Adobe's security advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS assigns just a 0.2% probability of exploitation within 30 days (10th percentile), indicating low near-term exploitation risk.
What to do: Update Acrobat Reader to the latest release per Adobe's security bulletin for this CVE — the provided data lacks fixed version numbers, so verify the exact affected and patched builds there. Until patched, avoid opening PDFs and other documents from untrusted sources, and consider sandboxing or restricting Acrobat for email-delivered files. With no public PoC and low EPSS, immediate risk is low, but patching should not be deferred given the near-universal deployment base.
Estimated exposure
mass≈1 billion+ users (Acrobat Reader is the dominant desktop PDF reader) — Acrobat Reader is the most widely deployed desktop PDF viewer, with cumulative installations reported in the billions, so deployment is effectively universal across consumer and enterprise endpoints.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.