ZDI-CAN-29409: ZDI-26-347: Adobe Acrobat Reader DC Multimedia Rendition Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47913.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29409?
ZDI-CAN-29409 has a CVSS rating of 7.8, indicating a high severity risk.
How does ZDI-CAN-29409 allow exploitation?
ZDI-CAN-29409 allows remote code execution through a use-after-free vulnerability that requires user interaction, such as visiting a malicious webpage or opening a malicious file.
Which software is affected by ZDI-CAN-29409?
ZDI-CAN-29409 affects Adobe Acrobat Reader DC.
What actions should users take regarding ZDI-CAN-29409?
Users should avoid visiting untrusted links or opening suspicious files to mitigate the risk associated with ZDI-CAN-29409.
Is there a patch available for ZDI-CAN-29409?
At this time, users should check for updates from Adobe for any patches related to ZDI-CAN-29409.