Acrobat Reader | Use After Free (CWE-416)
CVE-2024-49530

7HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
10 December 2024

Summary

Adobe Acrobat Reader versions 20 and 24 have been identified to contain a Use After Free vulnerability that poses a risk of arbitrary code execution. This vulnerability requires user interaction, as it can only be exploited if a user opens a specifically crafted malicious file. The effective exploitation of this flaw could allow an attacker to execute arbitrary code in the context of the user. Users are advised to be cautious with PDF files from untrusted sources to mitigate potential risks.

Affected Version(s)

Acrobat Reader 0 <= 20.005.30710

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre Database
.