ZDI-CAN-29886: ZDI-26-349: Adobe Acrobat Pro DC Annots.api Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-47915.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29886?
ZDI-CAN-29886 has a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-CAN-29886?
To fix ZDI-CAN-29886, ensure that you update Adobe Acrobat Pro DC to the latest version provided by the vendor.
What causes the ZDI-CAN-29886 vulnerability?
ZDI-CAN-29886 is caused by a use-after-free condition within the Annots.api component of Adobe Acrobat Pro DC.
What impacts does ZDI-CAN-29886 have?
ZDI-CAN-29886 allows remote attackers to execute arbitrary code, which can compromise the security of affected systems.
Is user interaction needed for exploiting ZDI-CAN-29886?
Yes, user interaction is required, as the target must either visit a malicious page or open a malicious file to exploit ZDI-CAN-29886.