CVE-2024-49535

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 10, 2024
Updated: Dec 18, 2024
CWE ID 611

Summary

CVE-2024-49535 is a newly disclosed vulnerability that impacts Adobe Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, and 20.005.30710, and older releases. The issue involves an Improper Restriction of XML External Entity Reference (XXE) that may result in arbitrary code execution. Malicious XML input can be provided to the software, which in turn may lead to data disclosure or potentially code execution due to the referencing of external entities. Notably, this vulnerability hinges on user interaction, meaning that a victim must process a malicious XML document for an attack to be successful.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat Reader DC
  • Adobe Acrobat
  • Adobe Acrobat Reader

Affected Vendors

  • Adobe