Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious PDF file. This could lead to unauthorized access to personal data or the installation of malicious software.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw occurs when the application writes data past the end of an intended buffer while processing a PDF file. An attacker can exploit this by convincing a user to open a maliciously crafted document. Successful exploitation allows for arbitrary code execution within the security context of the logged-in user. The attack vector is classified as local because it requires the file to be opened on the victim's machine, and it carries a CVSS base score of 7.8.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: advisory: Initial advisory published by Adobe and NVD