CVE-2024-49535
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-49535 is a newly disclosed vulnerability that impacts Adobe Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, and 20.005.30710, and older releases. The issue involves an Improper Restriction of XML External Entity Reference (XXE) that may result in arbitrary code execution. Malicious XML input can be provided to the software, which in turn may lead to data disclosure or potentially code execution due to the referencing of external entities. Notably, this vulnerability hinges on user interaction, meaning that a victim must process a malicious XML document for an attack to be successful.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Acrobat DC
- Adobe Acrobat Reader DC
- Adobe Acrobat
- Adobe Acrobat Reader
Affected Vendors
- Adobe