Acrobat Reader Vulnerability Could Lead to Arbitrary Code Execution
CVE-2024-41869

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
13 September 2024

Badges

πŸ“° News Worthy

Summary

CVE-2024-41869 is a vulnerability in Adobe Acrobat Reader that could lead to arbitrary code execution. It affects various versions of Acrobat Reader and requires user interaction to exploit. There is currently no evidence of exploitation by ransomware groups. Adobe has released a fix, but a PoC exploit for the vulnerability has been detected, prompting users to apply the update as soon as possible to mitigate potential risks.

Affected Version(s)

Acrobat Reader 0 <= 24.003.20054

News Articles

Adobe completes fix for Reader bug with known PoC exploit (CVE-2024-41869) - Help Net Security

Among the security updates released by Adobe on Tuesday are those for Acrobat and Reader, which fix CVE-2024-45112 and CVE-2024-41869.

4 months ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • πŸ“°

    First article discovered by Help Net Security

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database1 News Article(s)
.