Improper Restriction of XML External Entity Reference Vulnerability in Acrobat Reader by Adobe
CVE-2024-49535

6.3MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
10 December 2024

Summary

An Improper Restriction of XML External Entity Reference vulnerability exists in Acrobat Reader, affecting multiple versions. This security flaw enables an attacker to craft malicious XML documents that could invoke external entities. When processed by the application, this can lead to significant security risks, including arbitrary code execution and unauthorized data access. User interaction is required for exploitation, as the victim must open the specially crafted XML file, highlighting the importance of cautious document handling.

Affected Version(s)

Acrobat Reader 0 <= 20.005.30710

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.