Executive brief
Adobe Acrobat Reader, a widely used application for viewing and managing PDF documents, is affected by a security flaw that allows for unauthorized code execution. An attacker could gain control over a user's computer if the user is tricked into opening a specially crafted, malicious PDF file. This could lead to the theft of sensitive information, system disruption, or further malware installation on the affected device.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in multiple versions of Adobe Acrobat Reader. The flaw is triggered when the application processes a specially crafted PDF file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious document, potentially achieving arbitrary code execution within the security context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Adobe has addressed this issue in security bulletin APSB20-48.
Affected products
- Adobe Acrobat Reader 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier
Timeline
- 2026-06-23: disclosed: NVD Published Date
- 2026-06-23: advisory: Adobe security bulletin APSB20-48 referenced