Improper Restriction of XML External Entity Reference Vulnerability in Acrobat Reader by Adobe
CVE-2024-49535
6.3MEDIUM
Summary
An Improper Restriction of XML External Entity Reference vulnerability exists in Acrobat Reader, affecting multiple versions. This security flaw enables an attacker to craft malicious XML documents that could invoke external entities. When processed by the application, this can lead to significant security risks, including arbitrary code execution and unauthorized data access. User interaction is required for exploitation, as the victim must open the specially crafted XML file, highlighting the importance of cautious document handling.
Affected Version(s)
Acrobat Reader 0 <= 20.005.30710
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published