PT-2024-3543 · Adobe · Acrobat Reader+1

Published

2024-05-14

·

Updated

2024-12-02

·

CVE-2024-34097

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions prior to 2020 Adobe Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Adobe Acrobat 2020 Acrobat Reader 2020
Description The issue is related to a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, where a victim must open a malicious file. This vulnerability is associated with the use of memory after it has been freed.
Recommendations For Adobe Acrobat versions prior to 2020, update to a newer version to mitigate the risk. For Adobe Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier, update to a newer version to mitigate the risk. For Adobe Acrobat 2020, update to a newer version to mitigate the risk. For Acrobat Reader 2020, update to a newer version to mitigate the risk. As a temporary workaround, consider avoiding the use of the vulnerable Annotation feature in Adobe Acrobat Reader DC until a patch is available.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-03845
CVE-2024-34097
ZDI-24-478

Affected Products

Acrobat Reader
Acrobat