Acrobat Mobile Sign Vulnerable to Path Traversal Attacks
CVE-2024-34129

7.5HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
13 June 2024

Summary

Adobe Acrobat Mobile Sign for Android, specifically versions 24.4.2.33155 and earlier, is susceptible to a path traversal vulnerability. This security issue allows attackers to circumvent intended security measures, potentially gaining unauthorized access to files and directories located outside of the designated restricted area. Furthermore, the vulnerability can be exploited to overwrite arbitrary files on the device. Notably, exploitation does not require any user interaction, posing a significant risk as the complexity of executing the attack is high.

Affected Version(s)

Acrobat Mobile Sign Android 0 <= 24.4.2.33155

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.