ZDI-CAN-29433: ZDI-26-346: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-47924.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29433?
The severity of ZDI-CAN-29433 is rated at a risk score of 26.
How do I fix ZDI-CAN-29433?
To fix ZDI-CAN-29433, update to the latest version of Adobe Acrobat Reader DC provided by Adobe.
What is the impact of ZDI-CAN-29433?
The impact of ZDI-CAN-29433 includes potential disclosure of sensitive information.
What type of vulnerability is ZDI-CAN-29433?
ZDI-CAN-29433 is an annotation use-after-free information disclosure vulnerability.
Who can exploit ZDI-CAN-29433?
Remote attackers can exploit ZDI-CAN-29433, but user interaction is required.