CVE-2024-20749
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Feb 15, 2024
Updated: Mar 5, 2024
CWE ID 125
Summary
CVE-2024-20749 is a newly disclosed vulnerability affecting Acrobat Reader versions 20.005.30539, 23.008.20470, and older. This issue constitutes an out-of-bounds read vulnerability, whereby an attacker can manipulate data beyond allocated memory, potentially exposing sensitive information. By exploiting this flaw, threat actors may bypass Address Space Layout Randomization (ASLR) protections and gain unauthorized access to system memory. To trigger the vulnerability, a user must open a specially crafted file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Acrobat DC
- Adobe Acrobat Reader
- Adobe Acrobat
- Adobe Acrobat Reader DC
Affected Vendors
- Adobe