Acrobat Reader Vulnerability Could Lead to Arbitrary Code Execution
CVE-2024-41869
7.8HIGH
Summary
CVE-2024-41869 is a vulnerability in Adobe Acrobat Reader that could lead to arbitrary code execution. It affects various versions of Acrobat Reader and requires user interaction to exploit. There is currently no evidence of exploitation by ransomware groups. Adobe has released a fix, but a PoC exploit for the vulnerability has been detected, prompting users to apply the update as soon as possible to mitigate potential risks.
Affected Version(s)
Acrobat Reader 0 <= 24.003.20054
News Articles
Help Net SecurityCVE-2024-41869
Adobe completes fix for Reader bug with known PoC exploit (CVE-2024-41869) - Help Net Security
Among the security updates released by Adobe on Tuesday are those for Acrobat and Reader, which fix CVE-2024-45112 and CVE-2024-41869.
4 months ago
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
- π°
First article discovered by Help Net Security
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database1 News Article(s)