CyberzSOC

Publication detail
← Back to advisories & guidance

2024-095: Critical vulnerabilities in Adobe Products ↗ source

September 12, 2024 CERT-EU Advisory

Summary

When exploited, these vulnerabilities could allow an attacker to execute arbitrary code [1]. A publicly available proof-of-concept exploit exists for one of the vulnerabilities [2]. The vulnerability CVE-2024-41869, with a CVSS score of 7.8, is a use after free flaw that could lead to remote code execution when opening a specially crafted PDF document. The vulnerability CVE-2024-45112, with a CVSS score of 8.6, is a type confusion vulnerability that could lead to remote code execution. The following products are affected: CERT-EU strongly recommends updating affected products to a fixed version [2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-41869 7.8 High Adobe Acrobat Reader Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could …
CVE-2024-45112 7.8 High Adobe Acrobat Reader Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.