ZDI-26-354: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47919.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-354?
The severity of ZDI-26-354 is rated at 7.8 on the CVSS scale, indicating a high risk of remote code execution.
How do I fix ZDI-26-354?
To fix ZDI-26-354, update to the latest version of Adobe Acrobat Reader DC that includes the security patch addressing this vulnerability.
What are the potential impacts of ZDI-26-354?
The potential impacts of ZDI-26-354 include unauthorized remote code execution, which could allow attackers to take control of the affected system.
Is user interaction required to exploit ZDI-26-354?
Yes, user interaction is required to exploit ZDI-26-354 as the target must open a malicious file or visit a malicious page.
What versions of Adobe Acrobat Reader DC are affected by ZDI-26-354?
Adobe Acrobat Reader DC installations that have not been updated with the security patch for ZDI-26-354 are vulnerable.