Executive brief
Adobe Acrobat Reader, widely used to view and interact with PDF documents across enterprises and personal use, is affected by a use-after-free vulnerability that allows attackers to execute arbitrary code with the permissions of the logged-in user. An attacker can exploit this by crafting a malicious PDF file and tricking a user into opening it, potentially leading to complete system compromise, data theft, or lateral movement within a network.
Technical details
This vulnerability is a use-after-free (CWE-416) memory safety issue in Adobe Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier. The vulnerability requires user interaction—a victim must open a malicious PDF file—and allows arbitrary code execution in the security context of the current user. The attack vector is network-based, as a malicious PDF can be delivered via email or a web server. No authentication is required for exploitation. As of the advisory date, there is no indication of active exploitation in the wild, but patches should be prioritized given the severity and user-facing nature of the application.
Affected products
- Adobe Acrobat Reader 24.001.30307, 24.001.30308, 25.001.21265 and earlier
Timeline
- 2026-03-10: disclosed: Advisory published