ZDI-CAN-29477: ZDI-26-344: Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-47923.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29477?
ZDI-CAN-29477 has been assigned a risk score of 26, indicating it is a noteworthy vulnerability.
How do I fix ZDI-CAN-29477?
To mitigate ZDI-CAN-29477, ensure that you are using the latest version of Adobe Acrobat Reader DC, as updates often contain patches for known vulnerabilities.
What type of attack does ZDI-CAN-29477 enable?
ZDI-CAN-29477 allows remote attackers to disclose sensitive information by requiring user interaction to access malicious content.
Which software is affected by ZDI-CAN-29477?
ZDI-CAN-29477 specifically affects Adobe Acrobat Reader DC installations.
What is required for an attacker to exploit ZDI-CAN-29477?
The attacker needs the user to visit a malicious page or open a malicious file for ZDI-CAN-29477 to be exploited.