Type Confusion Vulnerability in Adobe Acrobat Reader Could Lead to Arbitrary Code Execution
CVE-2024-45112
7.8HIGH
Summary
Adobe Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, and 24.003.20054 experience a Type Confusion vulnerability that may allow attackers to execute arbitrary code in the context of the current user. This vulnerability arises when a resource is accessed using an incompatible object type, resulting in a logic error that can be exploited. Successful exploitation necessitates user interaction, as the targeted victim must open a specially crafted malicious file that triggers the vulnerability.
Affected Version(s)
Acrobat Reader 0 <= 24.003.20054
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database