ZDI-26-344: Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-47923.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-344?
ZDI-26-344 is classified as a risk level 26 vulnerability, indicating a serious potential threat.
How do I fix ZDI-26-344?
To mitigate ZDI-26-344, ensure you are using the latest version of Adobe Acrobat Reader DC, which includes security patches.
What types of information can be disclosed due to ZDI-26-344?
ZDI-26-344 can lead to the disclosure of sensitive information stored in the affected Adobe Acrobat Reader DC installations.
Is user interaction required for the exploitation of ZDI-26-344?
Yes, user interaction is required as the victim must open a malicious file or visit a harmful webpage to exploit ZDI-26-344.
What software is affected by ZDI-26-344?
ZDI-26-344 specifically affects Adobe Acrobat Reader DC installations.