ZDI-26-347: Adobe Acrobat Reader DC Multimedia Rendition Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47913.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-347?
ZDI-26-347 has a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-26-347?
To fix ZDI-26-347, ensure that you update Adobe Acrobat Reader DC to the latest version provided by Adobe.
What type of vulnerability is ZDI-26-347?
ZDI-26-347 is a use-after-free vulnerability that allows remote code execution.
What must a user do to be affected by ZDI-26-347?
A user must visit a malicious page or open a malicious file for ZDI-26-347 to be exploited.
Who is affected by ZDI-26-347?
Users of Adobe Acrobat Reader DC are affected by the ZDI-26-347 vulnerability.