CVE-2024-39426

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 14, 2024
Updated: Aug 15, 2024
CWE ID 125

Summary

CVE-2024-39426 is a newly disclosed vulnerability that impacts Adobe Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, and 24.001.30123, and earlier. This issue is classified as an out-of-bounds read vulnerability, where the software fails to correctly parse a maliciously crafted file. Consequently, it may read data beyond the allocated memory, potentially allowing an attacker to execute code in the context of the current user. For this exploit to be effective, the victim needs to open the malicious file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat
  • Adobe Acrobat Reader
  • Adobe Acrobat Reader DC

Affected Vendors

  • Adobe