Improper Restriction of XML External Entity Reference Vulnerability in Acrobat Reader by Adobe
CVE-2024-49535

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
10 December 2024

Summary

An Improper Restriction of XML External Entity Reference vulnerability exists in Acrobat Reader, affecting multiple versions. This security flaw enables an attacker to craft malicious XML documents that could invoke external entities. When processed by the application, this can lead to significant security risks, including arbitrary code execution and unauthorized data access. User interaction is required for exploitation, as the victim must open the specially crafted XML file, highlighting the importance of cautious document handling.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.