First published: Tue Mar 18 2025(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-271561.
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ZDI-CAN-26251 has been assigned a high severity rating due to its ability to allow remote code execution.
To mitigate the ZDI-CAN-26251 vulnerability, users should update their Adobe Acrobat Reader DC to the latest version provided by Adobe.
The impact of ZDI-CAN-26251 includes potential unauthorized access and control of the affected system through remote code execution.
Yes, user interaction is required to exploit ZDI-CAN-26251 as the target must visit a malicious page or open a malicious file.
ZDI-CAN-26251 affects Adobe Acrobat Reader DC installations.