PT-2024-4259 · Adobe · Acrobat Mobile Sign
Published
2024-06-11
·
Updated
2024-08-07
·
CVE-2024-34129
CVSS v3.1
7.5
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Acrobat Mobile Sign Android versions prior to 24.4.2.33156
Description
The issue is related to an improper limitation of a pathname to a restricted directory, which could result in a security feature bypass. An attacker could exploit this to access files and directories outside the restricted directory and overwrite arbitrary files. Exploitation does not require user interaction, and the attack complexity is high.
Recommendations
For versions prior to 24.4.2.33156, update to a version later than 24.4.2.33155 to resolve the issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat Mobile Sign