PT-2024-4259 · Adobe · Acrobat Mobile Sign

Published

2024-06-11

·

Updated

2024-08-07

·

CVE-2024-34129

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Acrobat Mobile Sign Android versions prior to 24.4.2.33156
Description The issue is related to an improper limitation of a pathname to a restricted directory, which could result in a security feature bypass. An attacker could exploit this to access files and directories outside the restricted directory and overwrite arbitrary files. Exploitation does not require user interaction, and the attack complexity is high.
Recommendations For versions prior to 24.4.2.33156, update to a version later than 24.4.2.33155 to resolve the issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04746
CVE-2024-34129

Affected Products

Acrobat Mobile Sign