AI analysis
Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known.
What to do: Upgrade Acrobat Reader to the fixed release identified in Adobe's security bulletin (no specific fixed version is included in this data), using Reader's built-in updater or enterprise deployment tooling and verifying the installed version via Help > About. Until patched, discourage opening PDFs from untrusted sources and apply email gateway filtering of attachments. No public PoC or in-the-wild exploitation is known, so standard patch-cycle timelines are defensible, though high-volume PDF-handling users should be prioritized.
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the dominant desktop PDF reader, with 1B+ cumulative installs) — Acrobat Reader is the de facto default PDF viewer on a very large share of enterprise and consumer desktops, so even a subset of its 1B+ historical install base implies far more users than most enterprise software flaws affect.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.