CVE-2024-39420

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Aug 14, 2024
Updated: Sep 16, 2024
CWE ID 367

Summary

CVE-2024-39420 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability affecting Adobe Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, and 24.003.20054. This issue arises when a change in the timing of actions alters the state of a resource, enabling an attacker to manipulate it maliciously before it's used. Arbitrary code execution can occur as a result, requiring user interaction, such as opening a specially crafted file to exploit the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat
  • Adobe Acrobat Reader
  • Adobe Acrobat Reader DC

Affected Vendors

  • Adobe