Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe acrobat Adobe acrobat Dc Adobe acrobat Reader Adobe acrobat Reader Dc |
|
CPEs | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
|
Vendors & Products |
Adobe
Adobe acrobat Adobe acrobat Dc Adobe acrobat Reader Adobe acrobat Reader Dc |
Wed, 11 Dec 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 10 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Dec 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
Title | Acrobat Reader | Out-of-bounds Read (CWE-125) | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-12-11T12:04:31.526Z
Reserved: 2024-10-15T15:35:47.031Z
Link: CVE-2024-49534

Updated: 2024-12-11T12:04:31.526Z

Status : Analyzed
Published: 2024-12-10T20:15:18.743
Modified: 2025-02-06T18:27:41.457
Link: CVE-2024-49534

No data.