AI analysis
Adobe Acrobat Reader contains a use-after-free memory corruption flaw (CWE-416) that occurs when the application references freed memory while processing a crafted file. The bug is triggered locally when a victim opens an attacker-supplied malicious file, typically a PDF, in an affected Reader build, so no network-facing service is involved and user interaction is required. Successful exploitation allows arbitrary code execution in the context of the current user, meaning an attacker gains the victim's privileges, which can mean full account compromise if that user runs with administrator rights. Anyone running an affected version of Acrobat Reader is exposed; the source data does not enumerate specific version ranges, so defenders should check Adobe's security bulletin for the exact affected and fixed builds. Exploitation status is currently quiet: there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
What to do: Update Acrobat Reader to the fixed release identified in Adobe's security bulletin for this CVE once published, covering the Reader builds Adobe lists as affected. Until patching is complete, treat unsolicited PDFs and files from untrusted sources as suspect, since exploitation requires a victim to open the malicious file, and keep Reader's Protected Mode (sandbox) enabled to constrain any code execution. Given the low EPSS and absence of a public PoC or KEV listing, there is no current evidence of active targeting, so routine patch cadence is sufficient.
Estimated exposure
mass≈1 billion+ potential installations (Acrobat Reader is the dominant desktop PDF viewer) — Adobe has long cited over one billion Acrobat Reader installations and the product is the default PDF viewer across much of the Windows and macOS installed base, so essentially every desktop fleet contains at least some affected…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.