Acrobat Reader | Use After Free (CWE-416)
CVE-2024-49530
7HIGH
Summary
Adobe Acrobat Reader versions 20 and 24 have been identified to contain a Use After Free vulnerability that poses a risk of arbitrary code execution. This vulnerability requires user interaction, as it can only be exploited if a user opens a specifically crafted malicious file. The effective exploitation of this flaw could allow an attacker to execute arbitrary code in the context of the user. Users are advised to be cautious with PDF files from untrusted sources to mitigate potential risks.
Affected Version(s)
Acrobat Reader 0 <= 20.005.30710
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database