AI analysis
Adobe Acrobat Reader contains an integer overflow or wraparound flaw (CWE-190) that can result in arbitrary code execution in the context of the current user. Triggering the flaw requires user interaction: a victim must open a maliciously crafted file, typically a PDF, delivered for example via email or web download. A successful attacker gains code execution with the victim's user privileges, which can enable malware installation, data theft, or lateral movement in enterprise environments. Any user running an affected Acrobat Reader version is at risk, but the specific affected version ranges and platforms are not listed in the available data and should be confirmed in Adobe's security bulletin. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a low 0.2% probability of exploitation within the next 30 days.
What to do: Consult Adobe's security bulletin for this CVE to determine which versions and platforms are affected, then deploy the corresponding patched release as soon as it is available. Until systems are patched, instruct users not to open PDF files from untrusted or unexpected sources, since exploitation requires opening a malicious file. Track the advisory for any updated affected-version or mitigation details.
Estimated exposure
masshundreds of millions of users (Acrobat Reader is one of the world's most widely deployed desktop applications) — Acrobat Reader is the dominant PDF viewer across consumer and enterprise desktops with an installed base in the hundreds of millions, and because the data omits a narrow affected version range, a large share of the user base is plausibly…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.