Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/acrobat/apsb24-07.html | Patch Vendor Advisory |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1901 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
01 Mar 2024, 23:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
First Time |
Microsoft
Adobe acrobat Dc Microsoft windows Adobe Adobe acrobat Adobe acrobat Reader Dc Apple Adobe acrobat Reader Apple macos |
|
References | () https://helpx.adobe.com/security/products/acrobat/apsb24-07.html - Patch, Vendor Advisory | |
References | () https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1901 - Third Party Advisory |
15 Feb 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Feb 2024, 14:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-15 13:15
Updated : 2024-03-01 23:06
NVD link : CVE-2024-20731
Mitre link : CVE-2024-20731
CVE.ORG link : CVE-2024-20731
JSON object : View
Products Affected
adobe
- acrobat
- acrobat_reader_dc
- acrobat_reader
- acrobat_dc
apple
- macos
microsoft
- windows
CWE
CWE-416
Use After Free