Use-After-Free Arbitrary Code Execution in Adobe Acrobat Reader
Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-corruption bug that can be leveraged for arbitrary code execution in the context of the current user. The flaw is triggered only with user interaction: the victim must open a malicious file, most plausibly a crafted PDF, making this a client-side, socially engineered attack rather than a remote, server-side one. A successful exploit lets an attacker run code with the victim's privileges, enabling data theft, malware installation, or further movement within the environment. Anyone running the affected Acrobat Reader releases is exposed, though the source data does not enumerate specific version ranges. There is currently no sign of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile).
· Adobe Acrobat Readermass
Integer Overflow Leading to Arbitrary Code Execution in Adobe Acrobat Reader
Adobe Acrobat Reader contains an integer overflow or wraparound flaw (CWE-190) that can result in arbitrary code execution in the context of the current user. Triggering the flaw requires user interaction: a victim must open a maliciously crafted file, typically a PDF, delivered for example via email or web download. A successful attacker gains code execution with the victim's user privileges, which can enable malware installation, data theft, or lateral movement in enterprise environments. Any user running an affected Acrobat Reader version is at risk, but the specific affected version ranges and platforms are not listed in the available data and should be confirmed in Adobe's security bulletin. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns a low 0.2% probability of exploitation within the next 30 days.
· Adobe Acrobat Readermass
Use-After-Free in Adobe Acrobat Reader Enables Arbitrary Code Execution
Adobe Acrobat Reader is affected by a use-after-free (CWE-416) memory-reuse flaw that, when successfully exploited, allows arbitrary code execution in the context of the current user. The flaw is triggered by user interaction: a victim must open a maliciously crafted file (typically a PDF) with an affected version of Reader. A successful attacker gains code execution with the victim's user privileges, enough to run malware, steal files, or pivot on the workstation, though no privilege escalation beyond the current user is implied. Everyone running a vulnerable build of Acrobat Reader is affected; given the product's ubiquity on enterprise and consumer desktops, the exposed population is very large, and exact affected version ranges should be taken from Adobe's security bulletin. There is no known public proof of concept, the issue is not on CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so exploitation status is currently none known.
· Adobe Acrobat Readermass
Out-of-Bounds Read Information Disclosure in Adobe Acrobat Reader (Doc Object)
Adobe Acrobat Reader contains an out-of-bounds read vulnerability (CWE-125) in its handling of Doc objects, per the ZDI-26-670 advisory, allowing the application to read beyond intended memory boundaries and potentially expose sensitive memory contents. An attacker triggers it by crafting a malicious PDF and convincing a victim to open it in Acrobat Reader, since exploitation requires local access and user interaction (AV:L/UI:R). A successful attack yields disclosure of sensitive information only; the CVSS vector (C:H/I:N/A:N) shows no integrity or availability impact and no implied code execution. All users of the affected Acrobat Reader/Acrobat DC versions are potentially exposed, though Adobe has not published the exact version ranges in the available data. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days (7th percentile).
· Adobe Acrobat Reader · Adobe Acrobat Pro DC (Doc Object handling, per ZDI-26-670)mass